An administrator wants to ensure that specific sensitive incident categories are restricted to a dedicated tier-2 response team. Which XSIAM construct should be configured to achieve this role-based operational segregation?
Correct. Access management features including roles and groups govern what data and incidents users can view.
Why this answer
Role-Based Access Control (RBAC) in XSIAM allows administrators to create custom roles with restricted permissions and assign users to specific user groups to control visibility over incidents and data.