CCCS-203B · Question #214
Your organization has configured a CIEM policy to grant access to a serverless compute service for users in the "DevOps" role. However, some users in this role report that they cannot access the…
The correct answer is D. The CIEM policy is not mapped to the appropriate cloud region for the serverless compute service. Option A: CIEM policies typically grant access by default unless explicitly restricted. The lack of a specific "allow" condition is unlikely to be the issue unless the policy is overly restrictive. Option B: CIEM manages entitlements at the group or role level, so manual…
Question
Your organization has configured a CIEM policy to grant access to a serverless compute service for users in the "DevOps" role. However, some users in this role report that they cannot access the service. What is the most likely reason for this issue, and how can it be resolved?
Options
- AThe policy does not include a condition to explicitly allow access to the serverless compute
- BThe users have not been manually added to the "DevOps" role in the cloud provider's IAM system.
- CThe cloud provider's native IAM policies are overriding the CIEM policy.
- DThe CIEM policy is not mapped to the appropriate cloud region for the serverless compute service.
How the community answered
(39 responses)- A33% (13)
- B5% (2)
- C13% (5)
- D49% (19)
Explanation
Option A: CIEM policies typically grant access by default unless explicitly restricted. The lack of a specific "allow" condition is unlikely to be the issue unless the policy is overly restrictive. Option B: CIEM manages entitlements at the group or role level, so manual addition of users to roles within the cloud provider's IAM system is not necessary if CIEM is configured correctly. Option C: CIEM policies are designed to work in conjunction with cloud provider IAM policies. Overrides could occur, but CIEM generally provides visibility into such conflicts, and misconfiguration is more likely. Option D: CIEM policies often need to be configured with specific regions in mind, especially for services like serverless compute that are region-dependent. Failing to map the policy to the appropriate region will prevent users from accessing the service.
Topics
Community Discussion
No community discussion yet for this question.