XDR-ENGINEER · Question #7
Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?
The correct answer is C. E1, E2, and E3. In permissive mode, a tenant's access controls are relaxed to allow broader data access across endpoints that fall within its authorized scope - in this scenario, E1, E2, and E3. Option C is correct because permissive mode lifts restrictive enforcement but still respects hard…
Question
Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which endpoint(s) data will be accessible?
Exhibit
Options
- AE1 only
- BE2 only
- CE1, E2, and E3
- DE1, E2, E3, and E4
How the community answered
(17 responses)- A12% (2)
- C82% (14)
- D6% (1)
Explanation
In permissive mode, a tenant's access controls are relaxed to allow broader data access across endpoints that fall within its authorized scope - in this scenario, E1, E2, and E3. Option C is correct because permissive mode lifts restrictive enforcement but still respects hard security boundaries; E4 remains inaccessible because it sits outside the tenant's authorized segment (likely in a strictly isolated or cross-tenant zone that no mode can override).
Why the distractors are wrong:
- A (E1 only) and B (E2 only) describe restrictive/default mode behavior, where access is tightly limited to a single endpoint.
- D (E1–E4) incorrectly assumes permissive mode means no boundaries - but even in permissive mode, E4's segment remains hard-blocked because it belongs to a separately enforced security boundary outside the tenant's reach.
Memory tip: Think of permissive mode as "open door within your building" - you can roam freely across your floors (E1, E2, E3), but the neighboring building (E4) stays locked regardless of your internal access level.
Topics
Community Discussion
No community discussion yet for this question.
