nerdexam
CrowdStrike

CCCS-203B · Question #164

You are using the CrowdStrike Cloud Infrastructure Entitlement Manager (CIEM) to audit cloud accounts. Which of the following accounts should be flagged for unnecessary access privileges?

The correct answer is B. An account with "write" access to storage buckets and "admin" access to IAM policies but only. Option A: This account adheres to best practices for privilege management. It is unlikely to be flagged for unnecessary access privileges. Option B: This account has unnecessary access privileges because its operations are limited to reading, yet it has higher permissions…

Cloud Infrastructure Entitlement Management

Question

You are using the CrowdStrike Cloud Infrastructure Entitlement Manager (CIEM) to audit cloud accounts. Which of the following accounts should be flagged for unnecessary access privileges?

Options

  • AAn account with permissions scoped to the "least privilege" principle and limited to specific
  • BAn account with "write" access to storage buckets and "admin" access to IAM policies but only
  • CAn account with "read-only" permissions to production resources but no login activity in 90 days.
  • DAn account with "limited" access to staging resources used for development purposes.

How the community answered

(32 responses)
  • A
    13% (4)
  • B
    78% (25)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Option A: This account adheres to best practices for privilege management. It is unlikely to be flagged for unnecessary access privileges. Option B: This account has unnecessary access privileges because its operations are limited to reading, yet it has higher permissions (write and admin). These excess privileges increase the attack surface and violate the principle of least privilege. This account should be reviewed and adjusted to remove unnecessary permissions. Option C: While inactivity might warrant review, "read-only" permissions do not pose a significant risk in terms of access privilege misuse. This account would more likely be flagged for inactivity rather than unnecessary privileges. Option D: This account aligns with the principle of least privilege and has access limited to a specific scope. It does not demonstrate unnecessary privileges.

Topics

#CIEM#Least Privilege#IAM Audit#Excessive Permissions

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice