nerdexam
CrowdStrike

CCCS-203B · Question #139

A security team is conducting an audit of user permissions in their cloud infrastructure monitored by CrowdStrike Falcon. Which of the following findings would indicate a high-risk security posture…

The correct answer is D. Multiple inactive user accounts retain administrator privileges and have not been used in several. Option A: Frequent access key rotation improves security and aligns with best practices, reducing exposure to credential compromise. Option B: Read-only access for developers in production is a controlled permission and does not present a high risk unless misused. Option C…

Identity and Access Management (CIEM)

Question

A security team is conducting an audit of user permissions in their cloud infrastructure monitored by CrowdStrike Falcon. Which of the following findings would indicate a high-risk security posture that requires immediate action?

Options

  • AAn administrator rotates their access keys every 30 days as part of a security policy.
  • BA developer has read-only access to a production environment for debugging purposes.
  • CA service account with limited permissions is used for an automated CI/CD pipeline.
  • DMultiple inactive user accounts retain administrator privileges and have not been used in several

How the community answered

(25 responses)
  • A
    20% (5)
  • B
    12% (3)
  • C
    4% (1)
  • D
    64% (16)

Explanation

Option A: Frequent access key rotation improves security and aligns with best practices, reducing exposure to credential compromise. Option B: Read-only access for developers in production is a controlled permission and does not present a high risk unless misused. Option C: Service accounts with limited permissions are a best practice for automated processes and do not pose a significant security risk. Option D: Inactive administrator accounts pose a major security risk because they could be compromised without detection. Attackers often target dormant accounts to escalate privileges and gain unauthorized access.

Topics

#IAM audit#inactive accounts#administrator privileges#least privilege

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice