CCCS-203B · Question #206
A company uses Falcon Cloud Security to enforce policies for AWS, Azure, and Google Cloud environments. The security team wants to create a policy that ensures all storage buckets across these cloud…
The correct answer is B. Apply a multi-cloud policy with the "Storage Security" category. Option A: While creating separate policies for each cloud provider is technically possible, using the "Network Security" category would not directly address storage bucket accessibility. It would unnecessarily complicate policy management. Option B: Multi-cloud policies in…
Question
A company uses Falcon Cloud Security to enforce policies for AWS, Azure, and Google Cloud environments. The security team wants to create a policy that ensures all storage buckets across these cloud providers are not publicly accessible. What should be the scope of the security policy to achieve this?
Options
- AApply separate policies for each cloud provider with the "Network Security" category.
- BApply a multi-cloud policy with the "Storage Security" category.
- CApply the policy to AWS only.
- DApply the policy to Azure only.
How the community answered
(19 responses)- A5% (1)
- B79% (15)
- C11% (2)
- D5% (1)
Explanation
Option A: While creating separate policies for each cloud provider is technically possible, using the "Network Security" category would not directly address storage bucket accessibility. It would unnecessarily complicate policy management. Option B: Multi-cloud policies in Falcon Cloud Security allow the creation of unified rules across AWS, Azure, and GCP. The "Storage Security" category is specifically designed for securing storage buckets, ensuring that they are not publicly accessible. Option C: Limiting the policy to AWS would not ensure protection for storage buckets in Azure The requirement specifies a multi-cloud approach. Option D: Focusing solely on Azure would leave AWS and GCP buckets unprotected, violating the stated requirement.
Topics
Community Discussion
No community discussion yet for this question.