CCCS-203B · Question #155
Which permissions are required to register an AWS cloud account with CrowdStrike Falcon?
The correct answer is B. A custom IAM role with permissions to access EC2, IAM, and CloudTrail services.. Option A: S3 permissions alone are insufficient for Falcon to fully monitor and secure the environment. While S3 access may be part of the overall integration, Falcon requires broader access to key services like EC2 and CloudTrail for comprehensive functionality. Option B: A cust
Question
Which permissions are required to register an AWS cloud account with CrowdStrike Falcon?
Options
- AOnly access to S3 buckets is needed to enable Falcon's data collection capabilities.
- BA custom IAM role with permissions to access EC2, IAM, and CloudTrail services.
- CFull administrative access to the root user of the AWS account.
- DPermissions to enable AWS Trusted Advisor to integrate with CrowdStrike Falcon.
How the community answered
(21 responses)- B86% (18)
- C5% (1)
- D10% (2)
Explanation
Option A: S3 permissions alone are insufficient for Falcon to fully monitor and secure the environment. While S3 access may be part of the overall integration, Falcon requires broader access to key services like EC2 and CloudTrail for comprehensive functionality. Option B: A custom IAM role with scoped permissions to access critical AWS services, such as EC2 (for workload visibility), IAM (for identity-related monitoring), and CloudTrail (for auditing and activity logs), is essential for proper integration with Falcon. Option C: Granting full administrative access to the root user is highly discouraged as it violates cloud security best practices. A custom IAM role with limited, scoped permissions ensures Falcon has the access it needs without over privileging. Option D: AWS Trusted Advisor is not a required service for integrating CrowdStrike Falcon. The focus is on enabling access to core cloud services like EC2, IAM, and CloudTrail, which are directly relevant to Falcon's capabilities.
Topics
Community Discussion
No community discussion yet for this question.