Courseiva
XSIAM Platform Architecture And DeploymenthardMultiple ChoiceObjective-mapped

XSIAM-Engineer XSIAM Platform Architecture And Deployment Practice Question

An organization has multiple business units sharing a single Cortex XSIAM tenant. Leadership requires that security analysts in Business Unit A can only view alerts and endpoints associated with their specific department, while global administrators retain full visibility. How must the deployment engineer configure access control to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure custom roles combined with folder-based access control, ensuring Business Unit A users are assigned to a role scoped exclusively to their designated folders.

Achieving strict data separation and analyst restriction within a single XSIAM tenant involves creating custom roles mapped to specific folder hierarchies and assigning users accordingly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Utilize XSOAR playbooks to automatically hide incidents belonging to Business Unit B from analysts' UI views.

    Why it's wrong here

    XSOAR playbooks do not replace core platform RBAC data scoping.

  • Create separate Cortex XSIAM tenants for each business unit and interconnect them using cross-tenant log forwarding.

    Why it's wrong here

    This introduces unnecessary management overhead when a single tenant with robust folder-based RBAC can suffice.

  • Modify the Broker VM configuration file to filter out logs from Business Unit B before sending them to the cloud.

    Why it's wrong here

    Filtering at the Broker VM drops data entirely rather than managing analyst RBAC visibility.

  • Configure custom roles combined with folder-based access control, ensuring Business Unit A users are assigned to a role scoped exclusively to their designated folders.

    Why this is correct

    Folder-based RBAC restricts the visibility of alerts, endpoints, and datasets to the assigned folder paths.

About these practice questions

This XSIAM-Engineer question is part of Courseiva's 200-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This XSIAM-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XSIAM-Engineer exam.