nerdexam
Palo_Alto_Networks

XSIAM-ENGINEER · Question #31

A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requirements: - Users…

The correct answer is A. Verify and confirm that SBAC mode under "Server Settings" is set to "Restrictive," and assign D. Use the pre-defined roles, assign the "Privileged IT Admin" role to the user or user group. To meet the requirements, the engineer must enable scope enforcement by setting SBAC mode to Restrictive and assigning the Europe endpoint group (EG:Europe) as the scope. For role assignment, the correct predefined role is Privileged IT Admin, since it allows endpoint…

Identity and Access Management

Question

A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requirements:

  • Users managing machines in Europe should be able to manage and control all endpoints and

installations, create profiles and policies, view alerts, and initiate Live Terminal, but only for endpoints in the Europe region.

  • Users managing machines in Europe should not be able to create, modify, or delete new or

existing user roles. The Europe region endpoints are identified by both of the following:

  • Endpoint Tag = "Europe-Servers" and Endpoint Group = "Europe" for servers in Europe
  • Endpoint Group = "Europe" and Endpoint Tag = "Europe-Workstation" for workstations in

Europe Which two sets of implementation actions should the engineer take? (Choose two.)

Options

  • AVerify and confirm that SBAC mode under "Server Settings" is set to "Restrictive," and assign
  • BUse the pre-defined roles, assign the "Instance Administrator" role to the user or user group
  • CVerify and confirm that SBAC mode under "Server Settings" is set to "Permissive," and assign
  • DUse the pre-defined roles, assign the "Privileged IT Admin" role to the user or user group

How the community answered

(44 responses)
  • A
    45% (20)
  • B
    20% (9)
  • C
    34% (15)

Explanation

To meet the requirements, the engineer must enable scope enforcement by setting SBAC mode to Restrictive and assigning the Europe endpoint group (EG:Europe) as the scope. For role assignment, the correct predefined role is Privileged IT Admin, since it allows endpoint management, policy creation, and Live Terminal but does not permit user role management.

Topics

#RBAC#SBAC restrictive mode#endpoint scope#role assignment

Community Discussion

No community discussion yet for this question.

Full XSIAM-ENGINEER Practice