CCCS-203B · Question #188
When using the Identity Analyzer feature in CrowdStrike CIEM to identify inactive users, which data source is primarily used to assess inactivity?
The correct answer is D. Audit trails of API calls and resource utilization. Option A: Network traffic logs are related to endpoint or network-level activity, not specific to cloud identities or IAM behavior. CIEM focuses on cloud-specific activity data like API calls and resource usage, making this an irrelevant data source. Option B: Security alerts…
Question
When using the Identity Analyzer feature in CrowdStrike CIEM to identify inactive users, which data source is primarily used to assess inactivity?
Options
- ANetwork traffic logs from connected endpoints.
- BHistorical security alerts from CrowdStrike Falcon.
- CCrowdStrike Falcon sensor telemetry.
- DAudit trails of API calls and resource utilization.
How the community answered
(48 responses)- A4% (2)
- B6% (3)
- C2% (1)
- D88% (42)
Explanation
Option A: Network traffic logs are related to endpoint or network-level activity, not specific to cloud identities or IAM behavior. CIEM focuses on cloud-specific activity data like API calls and resource usage, making this an irrelevant data source. Option B: Security alerts focus on threats and anomalies, not routine user activity patterns. CIEM uses operational data like API calls and resource usage to assess inactivity, which makes security alerts irrelevant for this purpose. Option C: Falcon sensor telemetry is used for endpoint detection and response, not cloud IAM activity. While it complements CIEM for overall security, it does not directly contribute to inactivity Option D: CIEM's Identity Analyzer uses audit trails, including API call records and resource utilization data, to detect inactivity. This ensures a holistic understanding of user behavior and accurately identifies users who no longer engage with cloud resources. This approach reduces false positives and enhances the security posture by identifying legitimate inactive accounts.
Topics
Community Discussion
No community discussion yet for this question.