CCCS-203B · Question #257
What should you do if an API key used for a cloud account integration is suspected to be compromised?
The correct answer is D. Rotate the API key and notify the Falcon administrator immediately. Option A: This is incorrect because disabling the cloud account integration might interrupt monitoring and leave the account vulnerable to threats. Option B: This is incorrect because privileges cannot be dynamically updated on a compromised key. A rotation is necessary to…
Question
What should you do if an API key used for a cloud account integration is suspected to be compromised?
Options
- ADisable the cloud account integration and restart the API client
- BUpdate the API key's privileges to restrict access temporarily
- CDelete the API key and create a new one with the same scopes
- DRotate the API key and notify the Falcon administrator immediately
How the community answered
(40 responses)- A10% (4)
- B5% (2)
- C13% (5)
- D73% (29)
Explanation
Option A: This is incorrect because disabling the cloud account integration might interrupt monitoring and leave the account vulnerable to threats. Option B: This is incorrect because privileges cannot be dynamically updated on a compromised key. A rotation is necessary to revoke the key and replace it securely. Option C: This is incorrect because simply deleting and recreating the key without proper notification and impact analysis might delay response efforts. Rotation is a more structured Option D: This is correct because rotating the API key ensures that the compromised key is no longer valid. Notifying the administrator helps assess potential security impacts and plan further mitigation steps.
Topics
Community Discussion
No community discussion yet for this question.