nerdexam
Palo_Alto_Networks

XSIAM-ENGINEER · Question #32

Administrators from Building 3 have been added to Cortex XSIAM to perform limited functions on a subset of endpoints. Custom roles have been created and applied to the administrators to limit their…

The correct answer is C. SBAC enabled in Restrictive Mode with the "EG:Building3" tag assigned to each administrator's. To enforce least privilege for Building 3 administrators, SBAC must be enabled in Restrictive Mode and the administrators' scope must be limited to EG:Building3. This ensures they can only manage endpoints within the Building 3 group, even if those endpoints are also part of…

Identity and Access Management

Question

Administrators from Building 3 have been added to Cortex XSIAM to perform limited functions on a subset of endpoints. Custom roles have been created and applied to the administrators to limit their permissions, but their access should also be constrained through the principle of least privilege according to the endpoints they are allowed to manage. All endpoints are part of an endpoint group named "Building3," and some endpoints may also be members of other endpoint groups. Which technical control will restrict the ability of the administrators to manage endpoints outside of their area of responsibility, while maintaining visibility to Building 3's endpoints?

Options

  • ASBAC enabled in Building 3's IP range with the "EG:Building3" tag assigned to each
  • BSBAC enabled in Permissive Mode with the "EG:Building3" tag assigned to each administrator's
  • CSBAC enabled in Restrictive Mode with the "EG:Building3" tag assigned to each administrator's
  • DSBAC enabled globally with the "EG:Building3" tag assigned to each administrator's scope

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    19% (7)
  • C
    68% (25)
  • D
    5% (2)

Explanation

To enforce least privilege for Building 3 administrators, SBAC must be enabled in Restrictive Mode and the administrators' scope must be limited to EG:Building3. This ensures they can only manage endpoints within the Building 3 group, even if those endpoints are also part of other groups, while blocking access to endpoints outside their responsibility.

Topics

#SBAC#restrictive mode#endpoint groups#least privilege

Community Discussion

No community discussion yet for this question.

Full XSIAM-ENGINEER Practice