CCCS-203B · Question #146
An organization has a custom IOM rule in Falcon Cloud Security to detect SSH connections from unauthorized IP addresses. However, the security team needs to update the rule to exclude a newly added…
The correct answer is C. Edit the IOM rule directly in the Falcon Cloud Security Console. Option A: Deleting and recreating the rule is inefficient and could lead to downtime or loss of historical data. The rule should be edited instead. Option B: There is no CLI functionality for modifying IOM rules in Falcon Cloud Security. All IOM rule management is handled…
Question
An organization has a custom IOM rule in Falcon Cloud Security to detect SSH connections from unauthorized IP addresses. However, the security team needs to update the rule to exclude a newly added internal IP range. What is the correct way to update this rule?
Options
- ADelete the existing IOM rule and create a new one with the updated IP range.
- BUse the Falcon CLI to modify the IOM rule in the underlying infrastructure.
- CEdit the IOM rule directly in the Falcon Cloud Security Console.
- DDisable the IOM rule and configure AWS Security Groups to handle IP whitelisting instead.
How the community answered
(27 responses)- A4% (1)
- B11% (3)
- C81% (22)
- D4% (1)
Explanation
Option A: Deleting and recreating the rule is inefficient and could lead to downtime or loss of historical data. The rule should be edited instead. Option B: There is no CLI functionality for modifying IOM rules in Falcon Cloud Security. All IOM rule management is handled through the console. Option C: Falcon Cloud Security provides a straightforward interface for editing existing custom IOM rules, including modifying IP ranges or other parameters. Option D: AWS Security Groups are not a replacement for Falcon Cloud Security's IOM rules. Security Groups are limited to network-level access control and do not offer the runtime detection capabilities of IOM rules.
Topics
Community Discussion
No community discussion yet for this question.