nerdexam
CrowdStrike

CCCS-203B · Question #115

What is the most effective action to take when a CIEM tool identifies an Azure Service Principal with overly permissive roles and no recent usage?

The correct answer is D. Review and remove unnecessary roles or scope for the Service Principal. Option A: Reassigning the Service Principal does not address the risk of overly permissive roles. Additionally, using an existing Service Principal for a new purpose can create security challenges Option B: While deleting the Service Principal may eliminate the risk, this…

Cloud Identity and Entitlement Management

Question

What is the most effective action to take when a CIEM tool identifies an Azure Service Principal with overly permissive roles and no recent usage?

Options

  • AReassign the Service Principal to a new application for future use.
  • BImmediately delete the Service Principal to eliminate the risk.
  • CAssign a "Reader" role to the Service Principal to limit its permissions.
  • DReview and remove unnecessary roles or scope for the Service Principal.

How the community answered

(32 responses)
  • A
    22% (7)
  • B
    13% (4)
  • C
    9% (3)
  • D
    56% (18)

Explanation

Option A: Reassigning the Service Principal does not address the risk of overly permissive roles. Additionally, using an existing Service Principal for a new purpose can create security challenges Option B: While deleting the Service Principal may eliminate the risk, this approach can disrupt any active dependencies. A more controlled remediation involves first reviewing and adjusting Option C: Changing the role to "Reader" may reduce risk, but it does not address whether the Service Principal is still necessary. The root cause (overly permissive roles and lack of usage) should be resolved. Option D: The most effective action is to evaluate the necessity of the Service Principal and remove any unnecessary roles or scopes. This minimizes risk while maintaining operational functionality if needed.

Topics

#CIEM#Azure Service Principal#overpermissioning#IAM remediation

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice