Question 1
Q1A SOC manager is designing a Role-Based Access Control (RBAC) strategy for a Cortex XDR environment. The organization requires a specific 'Tier 1 Analyst' role that allows users to view alerts and incidents, perform basic investigations, and add comments, but strictly prohibits them from executing response actions (such as isolating endpoints) or modifying global security policies. Which combination of permissions is the MOST appropriate configuration for this role?
Show answer & explanation
Correct answer: B
Cortex XDR allows for granular custom roles. To meet the requirement of viewing and investigating without response capabilities, a custom role must be created where View permissions are granted but Response Actions (like isolation or Live Terminal) are explicitly disabled. The Instance Administrator role is too powerful regardless of scoping.