nerdexam
CrowdStrike

CCCS-203B · Question #185

A security team is in the process of registering their organization's cloud accounts with CrowdStrike Falcon Cloud. During the registration process, they need to ensure that they have granted the…

The correct answer is D. Create a service-linked role in the cloud provider and allow CrowdStrike Falcon to assume the role. Option A: Installing Falcon sensors on workloads is important for endpoint protection but is not required before registering a cloud account. Registration enables cloud-level visibility, while sensors provide endpoint protection. Option B: Falcon uses role-based access to…

Cloud Account Registration and Management

Question

A security team is in the process of registering their organization's cloud accounts with CrowdStrike Falcon Cloud. During the registration process, they need to ensure that they have granted the required permissions for proper monitoring and threat detection. What is the first step they should take when registering a new cloud account?

Options

  • AInstall the CrowdStrike Falcon sensor on all virtual machines before starting the cloud registration
  • BManually configure CrowdStrike Falcon to ingest log data from the cloud provider's security audit
  • CGenerate an API key in the CrowdStrike Falcon Console and manually add it to the cloud
  • DCreate a service-linked role in the cloud provider and allow CrowdStrike Falcon to assume the role

How the community answered

(62 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    92% (57)

Explanation

Option A: Installing Falcon sensors on workloads is important for endpoint protection but is not required before registering a cloud account. Registration enables cloud-level visibility, while sensors provide endpoint protection. Option B: Falcon uses role-based access to retrieve security data instead of requiring manual log ingestion at the time of registration. Log integration can be set up later for additional visibility. Option C: While API keys are used for integrations, cloud account registration relies on role- based access rather than manually adding keys to IAM policies. Option D: CrowdStrike Falcon requires a service-linked role in the cloud provider (AWS, Azure, GCP) to assume the necessary permissions for security monitoring. This role allows Falcon to collect metadata, scan workloads, and detect threats without requiring manual log ingestion.

Topics

#cloud account registration#service-linked role#IAM permissions#multi-cloud onboarding

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice