nerdexam
CrowdStrike

CCCS-203B · Question #222

You are a cloud administrator tasked with enhancing security for your organization's cloud environment. Using CrowdStrike's Cloud Infrastructure Entitlement Manager (CIEM), you want to identify…

The correct answer is C. Use the "MFA Status" filter in CIEM's Identity Analyzer. Option A: The "Inactive Users Report" focuses on identifying accounts with minimal activity, not MFA status. This option is unrelated to the task of identifying MFA-enabled accounts. Option B: Failed login attempts might highlight suspicious activity or misconfigured accounts…

Cloud Infrastructure Entitlement Management (CIEM)

Question

You are a cloud administrator tasked with enhancing security for your organization's cloud environment. Using CrowdStrike's Cloud Infrastructure Entitlement Manager (CIEM), you want to identify accounts that have Multi-Factor Authentication (MFA) enabled. Which of the following is the most appropriate method to identify these accounts?

Options

  • ARun the "Inactive Users Report" and cross-reference it with CIEM recommendations.
  • BAnalyze failed login attempts from CIEM logs to infer MFA usage.
  • CUse the "MFA Status" filter in CIEM's Identity Analyzer.
  • DReview the "Account Permissions Summary" in the CIEM dashboard.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    87% (27)
  • D
    6% (2)

Explanation

Option A: The "Inactive Users Report" focuses on identifying accounts with minimal activity, not MFA status. This option is unrelated to the task of identifying MFA-enabled accounts. Option B: Failed login attempts might highlight suspicious activity or misconfigured accounts but do not directly correlate with MFA usage. Inferring MFA status from login failures is unreliable and prone to errors. Option C: The "MFA Status" filter in CIEM's Identity Analyzer is specifically designed to identify which accounts have MFA enabled. It provides a straightforward, automated method to determine MFA usage, ensuring accuracy and reducing manual effort. Using this built-in feature aligns with best practices for leveraging CIEM's capabilities. Option D: While the "Account Permissions Summary" provides an overview of permissions and access levels, it does not include information about MFA status. This option is irrelevant to identifying MFA-enabled accounts.

Topics

#CIEM#MFA status#Identity Analyzer#cloud IAM

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice