nerdexam
CrowdStrike

CCCS-203B · Question #204

After identifying an account with unnecessary access privileges using the CrowdStrike CIEM/Identity Analyzer, what is the best action to mitigate risks?

The correct answer is D. Implement the principle of least privilege by aligning permissions with the account's actual usage. Option A: While "read-only" permissions reduce risk, this blanket approach might hinder required operations if the account needs more specific access. Permissions should match the actual Option B: Using shared accounts violates best practices for identity and access management…

Cloud Identity and Access Management

Question

After identifying an account with unnecessary access privileges using the CrowdStrike CIEM/Identity Analyzer, what is the best action to mitigate risks?

Options

  • ADowngrade permissions to "read-only" for all resources.
  • BTransfer the account's permissions to a shared admin account for operational efficiency.
  • CDelete all permissions for the account immediately.
  • DImplement the principle of least privilege by aligning permissions with the account's actual usage.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    17% (5)
  • D
    73% (22)

Explanation

Option A: While "read-only" permissions reduce risk, this blanket approach might hinder required operations if the account needs more specific access. Permissions should match the actual Option B: Using shared accounts violates best practices for identity and access management (IAM). Shared accounts obscure accountability and increase the risk of privilege misuse. Option C: Deleting permissions without assessing operational needs can disrupt workflows and lead to unintended downtime. A more measured approach is required. Option D: The best approach to mitigate risks is to reduce the account's permissions to only what is necessary for its current activities. This minimizes the potential for misuse or exploitation while maintaining operational functionality.

Topics

#CIEM#least privilege#excessive permissions#remediation

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice