nerdexam
CrowdStrike

CCCS-203B · Question #23

What is the primary purpose of the CrowdStrike Cloud Infrastructure Entitlement Manager (CIEM) feature in a cloud environment?

The correct answer is C. Enforcing least-privilege access by identifying and remediating excessive permissions. Option A: Key management is typically the responsibility of dedicated tools or services like AWS KMS or Azure Key Vault. CIEM does not manage encryption keys or address data encryption Option B: While cost optimization is a key consideration in cloud management, CIEM…

Cloud Security Posture Management

Question

What is the primary purpose of the CrowdStrike Cloud Infrastructure Entitlement Manager (CIEM) feature in a cloud environment?

Options

  • AManaging encryption keys for sensitive cloud storage
  • BManaging cloud infrastructure costs by monitoring usage and recommending cost-saving
  • CEnforcing least-privilege access by identifying and remediating excessive permissions
  • DAutomating the deployment of cloud resources across multi-cloud environments

How the community answered

(34 responses)
  • B
    3% (1)
  • C
    94% (32)
  • D
    3% (1)

Explanation

Option A: Key management is typically the responsibility of dedicated tools or services like AWS KMS or Azure Key Vault. CIEM does not manage encryption keys or address data encryption Option B: While cost optimization is a key consideration in cloud management, CIEM specifically addresses identity and access management, not cost-saving measures. This is a common misconception as some cloud tools provide cost insights, but CIEM does not focus on financial Option C: CIEM focuses on improving security posture by identifying and reducing excessive permissions for identities (human and non-human) in cloud environments. This feature aligns with the principle of least privilege, which minimizes the potential attack surface and reduces risks arising from over-privileged accounts or roles. Option D: Automating resource deployment is a function of tools like Infrastructure as Code (IaC) platforms (e.g., Terraform, AWS CloudFormation). CIEM, however, is not designed for resource provisioning or deployment.

Topics

#CIEM#least-privilege access#cloud permissions#IAM

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice