nerdexam
CrowdStrike

CCCS-203B · Question #239

Your organization wants to automate the remediation of exposed AWS security groups that allow unrestricted access to port 22. What trigger condition should you configure in Falcon Fusion to ensure…

The correct answer is D. AWS Security Finding: Security Group allows 0.0.0.0/0 on port 22. Option A: Missing MFA is a critical security gap, but it pertains to user authentication rather than network access via security groups. Option B: High CPU usage may indicate a performance issue or potential compromise but is not directly linked to security group…

Cloud Security Automation and Remediation

Question

Your organization wants to automate the remediation of exposed AWS security groups that allow unrestricted access to port 22. What trigger condition should you configure in Falcon Fusion to ensure the workflow is activated for such findings?

Options

  • AAWS Security Finding: Missing MFA for IAM users.
  • BFalcon Sensor Alert: High CPU usage detected in an AWS instance.
  • CAWS Security Finding: Unused EC2 instance detected.
  • DAWS Security Finding: Security Group allows 0.0.0.0/0 on port 22.

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    8% (3)
  • D
    85% (34)

Explanation

Option A: Missing MFA is a critical security gap, but it pertains to user authentication rather than network access via security groups. Option B: High CPU usage may indicate a performance issue or potential compromise but is not directly linked to security group configurations. Option C: Although identifying unused resources is valuable for cost optimization, it is unrelated to the remediation of security group exposure. Option D: The correct trigger condition for automating remediation of an exposed security group is based on the specific AWS security finding that identifies security groups allowing unrestricted (0.0.0.0/0) access to port 22. This ensures the workflow targets the exact issue requiring remediation, such as tightening inbound rules for the security group.

Topics

#Falcon Fusion#automated remediation#AWS security groups#workflow triggers

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice