XSIAM-Engineer XSIAM Platform Architecture And Deployment Practice Question
An organization is setting up Cortex XSIAM and wishes to restrict administrative access so that specific Tier-2 analysts can modify prevention policies but cannot create new user accounts or modify RBAC settings. How should this be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom role with 'Policy Management' permissions enabled and 'User Management' permissions disabled.
Custom roles in Cortex XSIAM allow precise selection of permissions, granting policy management rights while withholding user management and RBAC administration privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant full administrator access and use audit logs to monitor unauthorized changes.
Why it's wrong here
This violates the principle of least privilege.
- ✓
Create a custom role with 'Policy Management' permissions enabled and 'User Management' permissions disabled.
Why this is correct
Custom roles enable granular separation of administrative duties.
- ✗
Assign the built-in 'Power User' role and rely on organizational policy guidelines.
Why it's wrong here
Power User includes broader privileges than desired.
- ✗
Use Active Directory group mapping to restrict menu items via CSS injection.
Why it's wrong here
CSS injection is not a supported method for access control.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 199 original XSIAM-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This XSIAM-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XSIAM-Engineer exam.