nerdexam
CrowdStrike

CCCS-203B · Question #238

An organization is using CrowdStrike's CIEM/Identity Analyzer to assess its cloud environment. During the analysis, it identifies several issues. Which of the following would be flagged as a primary…

The correct answer is A. Instances of unused roles with administrative privileges. Option A: CIEM/Identity Analyzer focuses on identifying risks related to permissions and roles in cloud environments. Unused roles, especially those with administrative privileges, represent a significant security risk as they can be exploited by malicious actors or abused…

Cloud Infrastructure Entitlement Management (CIEM)

Question

An organization is using CrowdStrike's CIEM/Identity Analyzer to assess its cloud environment. During the analysis, it identifies several issues. Which of the following would be flagged as a primary concern?

Options

  • AInstances of unused roles with administrative privileges.
  • BFirewall misconfigurations allowing unrestricted inbound traffic.
  • CData stored in unencrypted cloud storage buckets.
  • DOutdated operating systems running on virtual machines.

How the community answered

(24 responses)
  • A
    83% (20)
  • B
    4% (1)
  • C
    4% (1)
  • D
    8% (2)

Explanation

Option A: CIEM/Identity Analyzer focuses on identifying risks related to permissions and roles in cloud environments. Unused roles, especially those with administrative privileges, represent a significant security risk as they can be exploited by malicious actors or abused inadvertently. Identifying and remediating these issues aligns with CIEM's core purpose of ensuring least privilege access. Option B: Misconfigured firewalls pose significant risks, but CIEM does not deal with network- level security. This would be addressed by network security tools like cloud firewalls or security Option C: Although critical for data security, encryption of storage is not the focus of CIEM. Tools specific to storage configuration and compliance are used for this purpose. Option D: This is a vulnerability management issue, not an identity and permissions concern. It falls under the scope of VM monitoring or endpoint protection tools, not CIEM.

Topics

#CIEM#Identity Analyzer#unused roles#privileged access

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice