XSIAM-ENGINEER · Question #31
A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requirements: - Users…
The correct answer is A. Verify and confirm that SBAC mode under "Server Settings" is set to "Restrictive," and assign D. Use the pre-defined roles, assign the "Privileged IT Admin" role to the user or user group. To meet the requirements, the engineer must enable scope enforcement by setting SBAC mode to Restrictive and assigning the Europe endpoint group (EG:Europe) as the scope. For role assignment, the correct predefined role is Privileged IT Admin, since it allows endpoint…
Question
A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requirements:
- Users managing machines in Europe should be able to manage and control all endpoints and
installations, create profiles and policies, view alerts, and initiate Live Terminal, but only for endpoints in the Europe region.
- Users managing machines in Europe should not be able to create, modify, or delete new or
existing user roles. The Europe region endpoints are identified by both of the following:
- Endpoint Tag = "Europe-Servers" and Endpoint Group = "Europe" for servers in Europe
- Endpoint Group = "Europe" and Endpoint Tag = "Europe-Workstation" for workstations in
Europe Which two sets of implementation actions should the engineer take? (Choose two.)
Options
- AVerify and confirm that SBAC mode under "Server Settings" is set to "Restrictive," and assign
- BUse the pre-defined roles, assign the "Instance Administrator" role to the user or user group
- CVerify and confirm that SBAC mode under "Server Settings" is set to "Permissive," and assign
- DUse the pre-defined roles, assign the "Privileged IT Admin" role to the user or user group
How the community answered
(44 responses)- A45% (20)
- B20% (9)
- C34% (15)
Explanation
To meet the requirements, the engineer must enable scope enforcement by setting SBAC mode to Restrictive and assigning the Europe endpoint group (EG:Europe) as the scope. For role assignment, the correct predefined role is Privileged IT Admin, since it allows endpoint management, policy creation, and Live Terminal but does not permit user role management.
Topics
Community Discussion
No community discussion yet for this question.