Question 1
Q1A SOC Manager needs to configure Role-Based Access Control (RBAC) in Cortex XDR for a new Tier 1 Analyst team. This team requires the ability to view alerts and investigate incidents but must be strictly prohibited from executing response actions such as Live Terminal or isolating endpoints. Which predefined role or custom configuration best adheres to the principle of least privilege for this requirement?
Show answer & explanation
Correct answer: B
The 'Viewer' role is too restrictive as it may not allow full investigation capabilities like editing incident status or adding comments. A custom role is required to granularly grant investigation rights (View/Edit on Incidents) while explicitly denying Response Actions (None), satisfying the specific operational requirement.