nerdexam
CrowdStrike

CCCS-203B · Question #121

What is the best practice when configuring an assessment schedule in CrowdStrike's Cloud Security Posture Management (CSPM) module?

The correct answer is B. Configure assessments at a frequency that aligns with compliance or business requirements. Option A: Default settings may not always align with an organization's specific compliance needs or operational cadence. Reviewing and customizing scope and frequency ensures the assessments are optimized for the specific environment. Option B: Aligning assessment frequency…

Cloud Security Posture Management (CSPM)

Question

What is the best practice when configuring an assessment schedule in CrowdStrike's Cloud Security Posture Management (CSPM) module?

Options

  • AUse default settings without reviewing scope and frequency, as they are pre-optimized by
  • BConfigure assessments at a frequency that aligns with compliance or business requirements.
  • CSchedule assessments for each cloud account individually to avoid overlaps.
  • DRun assessments only during off-peak hours to avoid performance degradation in cloud resources.

How the community answered

(16 responses)
  • B
    88% (14)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Option A: Default settings may not always align with an organization's specific compliance needs or operational cadence. Reviewing and customizing scope and frequency ensures the assessments are optimized for the specific environment. Option B: Aligning assessment frequency with compliance or business requirements is the best practice. For example, compliance frameworks like SOC 2 or ISO 27001 may mandate daily or weekly assessments, while more frequent scans may be needed in dynamic environments. Option C: Scheduling assessments individually for each cloud account can be unnecessarily complex and prone to errors. CrowdStrike allows centralized scheduling for multiple accounts, simplifying management and ensuring comprehensive coverage. Option D: While off-peak scheduling may reduce resource contention in certain cases, CSPM assessments are non-intrusive and should prioritize security and compliance needs over resource availability. Waiting for off-peak hours may delay detection of vulnerabilities.

Topics

#CSPM#assessment scheduling#compliance alignment#Falcon configuration

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice