Fetch detailed fix information for a specific CIS benchmark rule

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Retrieves detailed information about a specific CIS benchmark rule including description, rationale, remediation steps, and for scanned resources: expected vs actual values and audit remarks

Request URL

https://{serverurl}/dcapi/scap/compliance/benchmark/rules/{ruleId}

Scope

DesktopCentralCloud.VulnerabilityMgmt.READCopied!

Header

Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Path Parameters

ruleIdstringMandatory

Rule identifier. Fetch from Get Benchmark Details response steps[].children[].itemId where type is rule

- Query Parameters

resourceIdlongOptional

Resource ID for scan results

collectionIdlongOptional

Collection ID for scan results

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url https://appdomains/dcapi/scap/compliance/benchmark/rules/{ruleId} \
  --header 'Authorization: Zoho-oauthtoken  d92d4xxxxxxxxxxxxx15f52'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
ruleIdstring

The queried rule ID

summarystring

Rule description (sanitized HTML)

rationalestring

Why this rule matters (sanitized HTML)

fixstring

Remediation instructions (sanitized HTML)

reasonstring

Expected vs actual values with HTML formatting. Only present when resourceId and collectionId are provided

- HTTP code 401

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Unauthorized error code: credentials missing, expired, or invalid

errorMsgstring

Authentication failure reason

- HTTP code 429

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Rate limit error code returned when the API call reached threshold

errorMsgstring

Rate limit exceeded message with retry guidance

Possible Response Codes

200HTTP code
401HTTP code
429HTTP code

Sample Response: HTTP 200

Rule details with scan results showing expected vs actual values

Copied!
  {
    "summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts",
    "reason": "<b>Expected value :</b> 5<br><br><b>Current value :</b> 10<br><br><b>Registry path :</b> HKLM\\SOFTWARE\\...",
    "fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0: Computer Configuration\\Policies\\Windows Settings\\Security Settings\\Account Policies\\Account lockout threshold",
    "ruleId": "1001",
    "rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful"
  }
                
Show full

Rule details without resource-specific scan data

Copied!
  {
    "summary": "Ensure Account lockout threshold is set to 5 or fewer invalid logon attempts",
    "fix": "To establish the recommended configuration via GP, set the following UI path to 5 or fewer but not 0",
    "ruleId": "1001",
    "rationale": "Setting an account lockout threshold reduces the likelihood that an online password brute force attack will be successful"
  }
                
Show full

Sample Response: HTTP 401

Authentication credentials are missing or invalid

Copied!
  {
    "errorMessage": "Authentication required",
    "errorCode": "UNAUTHORIZED"
  }
                
Show full

Sample Response: HTTP 429

API call threshold exceeded

Copied!
  {
    "errorMessage": "Rate limit exceeded. Retry after some time",
    "errorCode": "TOO_MANY_REQUESTS"
  }
                
Show full

Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.