nerdexam
CrowdStrike

CCCS-203B · Question #13

Which data sources does CrowdStrike CIEM primarily analyze to identify privileged accounts without multi-factor authentication (MFA)?

The correct answer is D. Cloud provider IAM policy configurations and MFA enforcement settings. Option A: Falcon focuses on endpoint activity and threat detection, which is unrelated to IAM configurations or MFA enforcement. CIEM is tailored to cloud IAM analysis. Option B: Email activity logs are unrelated to identifying privileged accounts or MFA enforcement. CIEM…

Cloud Infrastructure Entitlement Management (CIEM)

Question

Which data sources does CrowdStrike CIEM primarily analyze to identify privileged accounts without multi-factor authentication (MFA)?

Options

  • AEndpoint login logs collected by CrowdStrike Falcon.
  • BEmail activity logs from integrated cloud email platforms.
  • CFirewall access control lists (ACLs) for privileged IP ranges.
  • DCloud provider IAM policy configurations and MFA enforcement settings.

How the community answered

(32 responses)
  • B
    9% (3)
  • C
    3% (1)
  • D
    88% (28)

Explanation

Option A: Falcon focuses on endpoint activity and threat detection, which is unrelated to IAM configurations or MFA enforcement. CIEM is tailored to cloud IAM analysis. Option B: Email activity logs are unrelated to identifying privileged accounts or MFA enforcement. CIEM focuses on cloud provider IAM policies and MFA settings to detect misconfigurations Option C: Firewall ACLs are used to control network traffic and are not relevant to cloud IAM or MFA configurations. CIEM operates on IAM data and cloud provider configurations, not network- Option D: CIEM analyzes IAM policy configurations to identify accounts with privileged roles and cross-references these findings with MFA enforcement settings to determine which accounts are not protected by MFA. This approach ensures precise detection of misconfigured accounts that could pose security risks.

Topics

#CIEM#MFA enforcement#IAM policy analysis#privileged account detection

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice