# Fetch detailed fix information for a specific CIS benchmark rule Retrieves detailed information about a specific CIS benchmark rule including description, rationale, remediation steps, and for scanned resources: expected vs actual values and audit remarks. ## Endpoints `GET /dcapi/scap/compliance/benchmark/rules/{ruleId}` ## Request URL `https://[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)/dcapi/scap/compliance/benchmark/rules/{ruleId}` ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Path Parameters - **ruleId** `string` — Mandatory Rule identifier. Fetch from [Get Benchmark Details](https://www.manageengine.com/products/desktop-central/help/api/cloud/get-benchmark-details.html) response `steps[].children[].itemId` where type is rule. ### Query Parameters - **resourceId** `long` — Optional Resource ID for scan results. - **collectionId** `long` — Optional Collection ID for scan results. ## Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/benchmark/rules/{ruleId} \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json `JSON Object` - **ruleId** `string` The queried rule ID. - **summary** `string` Rule description (sanitized HTML). - **rationale** `string` Why this rule matters (sanitized HTML). - **fix** `string` Remediation instructions (sanitized HTML). - **reason** `string` Expected vs actual values with HTML formatting. Only present when `resourceId` and `collectionId` are provided. ### HTTP Code 401 #### Response Body — application/json `JSON Object` - **errorCode** `long` Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required). - **errorMsg** `string` Authentication failure reason. ### HTTP Code 429 #### Response Body — application/json `JSON Object` - **errorCode** `long` Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes. - **errorMsg** `string` Rate limit exceeded message with retry guidance. ## Possible Response Codes - **200** — HTTP code - **401** — HTTP code - **429** — HTTP code ## Sample Response: HTTP 200 ### Rule details with scan results showing expected vs actual values ```json { "summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts", "reason": "Expected value : 5

Current value : 10

Registry path : HKLM\\SOFTWARE\\...", "fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0: Computer Configuration\\Policies\\Windows Settings\\Security Settings\\Account Policies\\Account lockout threshold", "ruleId": "1001", "rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful" } ``` ### Rule details without resource-specific scan data ```json { "summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts", "fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0", "ruleId": "1001", "rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful" } ``` ## Sample Response: HTTP 401 ### Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ## Sample Response: HTTP 429 ### API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration — Time window for the threshold. Threshold — Number of API calls allowed within the specified duration. Lock Period — Wait time before consecutive API requests.