What Are the Default Access Control Options for a New Indicator?

What are the default Access Control options for a new Indicator?

  1. Visible to Just Me. Visible by All Roles is False, role required is pa_admin.
  2. Visible to Everyone. Visible by All Roles is True.
  3. Visible to Everyone. Visible by All Roles is False, role required is pa_admin. Source Reference Answer
  4. Visible to Just Me. Visible by All Roles is False.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam is checking your knowledge of Cortex XSOAR default ACL values, and the common trap is thinking 'Visible to Everyone' automatically means all roles have access.

The correct answer for default access control on a new Cortex XSOAR indicator is C: Visible to Everyone, Visible by All Roles is False, and the required role is pa_admin. This matches the most-liked community comment and the overall vote distribution.

Selecting B, because it correctly includes 'Visible to Everyone' but incorrectly sets 'Visible by All Roles' to True; the default keeps role-based visibility restricted with pa_admin as the required role.

Community Discussion (3 comments)

dam1211 👍 4 Selected: C
New indicators have Access Control default to 'Visible to' = Everyone, 'Visible by all roles' = False, and no Roles selected. The roles required to create an indicator are pa_admin, pa_power_user, or admin. Therefore, C is the correct answer.
Shdwklown 👍 2
Creating a new indicator suggest that B is best option here. New indicators default to "Visible to Everyone". Though, on several new indicators I built in both a D.C. and Xanadu instance had the "Visible to all roles" unselected, and no roles defined. None of the options seem to be correct, B is just the closest based on personal observations and testing. Though, C could be close if you interpret "role required is pa_admin" as meaning you need pa_admin to create an indicator. The question wording suggests that it's just looking for what the default settings are when creating an indicator though, so I'm still leaning towards B.
b3de868 👍 1
The default Access Control options for a new Indicator are generally set to be more restrictive to safeguard data security. While the exact defaults can depend on system configuration, typically, a new indicator may not be visible to all users by default. Here are the usual defaults: A. Visible to Just Me. Visible by All Roles is False, role required is pa_admin. This setting implies that by default, the indicator is only visible to the creator or users with the pa_admin role unless further configured to be visible to additional roles or users.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C correctly lists the three default access control components: visibility is set to Everyone, the 'Visible by All Roles' toggle is False, and the default role requirement is pa_admin. A highly upvoted community comment confirms that new indicators have 'Visible to' = Everyone, 'Visible by all roles' = False, and that indicator-creation/access roles include pa_admin. This exact combination appears only in option C.

Why the Other Options Are Wrong

A and D both say 'Visible to Just Me', which is not how Cortex XSOAR treats newly created indicators; they are shared by default rather than private to the creator. B has the right visibility value but incorrectly enables 'Visible by All Roles' as True, which would give every role access and contradicts the default role-specific restriction. C is the only option that matches all defaults without conflicting with the documented role behavior.

Community Comment Notes

The 4-like comment is the most useful because it directly states the default values and mentions pa_admin, pa_power_user, and admin as the roles involved, supporting C. A lower-voted comment recommended B based on personal testing, but it ignored the role-specific default in the ACL configuration. Another lower-voted comment argued for a more restrictive default, which is a common security misconception but does not match Cortex XSOAR's out-of-box behavior.

Official Reference

Exam Strategy

Remember the default ACL trio: Visible to Everyone, Visible by All Roles = False, and pa_admin as the required role. When answering, do not confuse 'visible to everyone' with 'all roles automatically visible'; the role toggle is set to False by default.

Related Analysis

Practice All CAS-PA Questions

Access 79 questions with complete answers and detailed explanations.

View Full CAS-PA Practice Test →

← Back to CAS-PA Study Guide