What Are the Default Access Control Options for a New Indicator?
What are the default Access Control options for a new Indicator?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam is checking your knowledge of Cortex XSOAR default ACL values, and the common trap is thinking 'Visible to Everyone' automatically means all roles have access.
The correct answer for default access control on a new Cortex XSOAR indicator is C: Visible to Everyone, Visible by All Roles is False, and the required role is pa_admin. This matches the most-liked community comment and the overall vote distribution.
Selecting B, because it correctly includes 'Visible to Everyone' but incorrectly sets 'Visible by All Roles' to True; the default keeps role-based visibility restricted with pa_admin as the required role.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
C correctly lists the three default access control components: visibility is set to Everyone, the 'Visible by All Roles' toggle is False, and the default role requirement is pa_admin. A highly upvoted community comment confirms that new indicators have 'Visible to' = Everyone, 'Visible by all roles' = False, and that indicator-creation/access roles include pa_admin. This exact combination appears only in option C.Why the Other Options Are Wrong
A and D both say 'Visible to Just Me', which is not how Cortex XSOAR treats newly created indicators; they are shared by default rather than private to the creator. B has the right visibility value but incorrectly enables 'Visible by All Roles' as True, which would give every role access and contradicts the default role-specific restriction. C is the only option that matches all defaults without conflicting with the documented role behavior.Community Comment Notes
The 4-like comment is the most useful because it directly states the default values and mentions pa_admin, pa_power_user, and admin as the roles involved, supporting C. A lower-voted comment recommended B based on personal testing, but it ignored the role-specific default in the ACL configuration. Another lower-voted comment argued for a more restrictive default, which is a common security misconception but does not match Cortex XSOAR's out-of-box behavior.Official Reference
Exam Strategy
Remember the default ACL trio: Visible to Everyone, Visible by All Roles = False, and pa_admin as the required role. When answering, do not confuse 'visible to everyone' with 'all roles automatically visible'; the role toggle is set to False by default.
Related Analysis
Practice All CAS-PA Questions
Access 79 questions with complete answers and detailed explanations.
View Full CAS-PA Practice Test →