CCCS-203B · Question #238
An organization is using CrowdStrike's CIEM/Identity Analyzer to assess its cloud environment. During the analysis, it identifies several issues. Which of the following would be flagged as a primary…
The correct answer is A. Instances of unused roles with administrative privileges. Option A: CIEM/Identity Analyzer focuses on identifying risks related to permissions and roles in cloud environments. Unused roles, especially those with administrative privileges, represent a significant security risk as they can be exploited by malicious actors or abused…
Question
An organization is using CrowdStrike's CIEM/Identity Analyzer to assess its cloud environment. During the analysis, it identifies several issues. Which of the following would be flagged as a primary concern?
Options
- AInstances of unused roles with administrative privileges.
- BFirewall misconfigurations allowing unrestricted inbound traffic.
- CData stored in unencrypted cloud storage buckets.
- DOutdated operating systems running on virtual machines.
How the community answered
(24 responses)- A83% (20)
- B4% (1)
- C4% (1)
- D8% (2)
Explanation
Option A: CIEM/Identity Analyzer focuses on identifying risks related to permissions and roles in cloud environments. Unused roles, especially those with administrative privileges, represent a significant security risk as they can be exploited by malicious actors or abused inadvertently. Identifying and remediating these issues aligns with CIEM's core purpose of ensuring least privilege access. Option B: Misconfigured firewalls pose significant risks, but CIEM does not deal with network- level security. This would be addressed by network security tools like cloud firewalls or security Option C: Although critical for data security, encryption of storage is not the focus of CIEM. Tools specific to storage configuration and compliance are used for this purpose. Option D: This is a vulnerability management issue, not an identity and permissions concern. It falls under the scope of VM monitoring or endpoint protection tools, not CIEM.
Topics
Community Discussion
No community discussion yet for this question.