# Fetch CIS compliance Profile Results for a Specific Resource Retrieves all CIS compliance profile results for a specific resource within a custom group, showing each benchmark profile's scan status, pass/fail percentage, and rules breakdown. ## Endpoint `GET /dcapi/scap/compliance/result/profiles/{resourceId}` ## Request ### Request URL `https://{serverurl}/dcapi/scap/compliance/result/profiles/{resourceId}` For server URL details, see [OAuth Authentication Endpoint Domain](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html). ### Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Request Parameters #### Path Parameters - **resourceId** `string` — Mandatory - Computer/resource ID. Fetch from [Get CG Association Details](https://www.manageengine.com/products/desktop-central/help/api/cloud/get-cg-association-details.html) resource listing. #### Query Parameters - **groupResourceId** `long` — Optional - Custom group resource ID. - **filter** `string` — Optional - Rule status filter. Values: `all`, `passed`, `failed`, `error`, `unknown`, `notApplicable`, `unscored`. - **appFilter** `string` — Optional - Applicability filter. Values: `all`, `1` (applicable only). - **scanStatus** `string` — Optional - Scan status filter. Values: `all`, `SCAN_COMPLETED`, `YET_TO_SCAN`. - **platformId** `long` — Optional - Platform ID for filtering. - **offset** `integer` — Optional - Pagination offset. - **limit** `integer` — Optional - Maximum number of results to return. - **collectionId** `long` — Optional - Collection ID of the compliance association. ### Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/result/profiles/{resourceId} \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response ### HTTP Code 200 Response body: `application/json` - `JSON Object` - **resourceName** `string` - Name of the computer. - **cgName** `string` - Custom group name. - **benchmarks** `JSON Array` - List of benchmark profiles with scan results. ### HTTP Code 401 Response body: `application/json` - `JSON Object` - **errorCode** `long` - Unauthorized error code: credentials missing, expired, or invalid. - **errorMsg** `string` - Authentication failure reason. ### HTTP Code 429 Response body: `application/json` - `JSON Object` - **errorCode** `long` - Rate limit error code returned when the API call reached threshold. - **errorMsg** `string` - Rate limit exceeded message with retry guidance. ### Possible Response Codes - **200** — HTTP code - **401** — HTTP code - **429** — HTTP code ### Sample Response: HTTP 200 Profile scan results for a specific resource. ```json { "resourceName": "WIN-SERVER-01", "benchmarks": [ { "result": "200/245 Rules Passed", "scapType": "XCCDF", "profileType": 1, "profileId": 50001, "title": "CIS Microsoft Windows Server 2019 Benchmark - Level 1", "successPercentage": 82 }, { "result": "NA", "scapType": "XCCDF", "profileType": 1, "profileId": 50002, "title": "CIS Microsoft Windows Server 2019 Benchmark - Level 2", "successPercentage": 0 } ], "cgName": "Production Servers" } ``` ### Sample Response: HTTP 401 Authentication credentials are missing or invalid. ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### Sample Response: HTTP 429 API call threshold exceeded. ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.