nerdexam
CrowdStrike

CCCS-203B · Question #257

What should you do if an API key used for a cloud account integration is suspected to be compromised?

The correct answer is D. Rotate the API key and notify the Falcon administrator immediately. Option A: This is incorrect because disabling the cloud account integration might interrupt monitoring and leave the account vulnerable to threats. Option B: This is incorrect because privileges cannot be dynamically updated on a compromised key. A rotation is necessary to…

Cloud Account Management

Question

What should you do if an API key used for a cloud account integration is suspected to be compromised?

Options

  • ADisable the cloud account integration and restart the API client
  • BUpdate the API key's privileges to restrict access temporarily
  • CDelete the API key and create a new one with the same scopes
  • DRotate the API key and notify the Falcon administrator immediately

How the community answered

(40 responses)
  • A
    10% (4)
  • B
    5% (2)
  • C
    13% (5)
  • D
    73% (29)

Explanation

Option A: This is incorrect because disabling the cloud account integration might interrupt monitoring and leave the account vulnerable to threats. Option B: This is incorrect because privileges cannot be dynamically updated on a compromised key. A rotation is necessary to revoke the key and replace it securely. Option C: This is incorrect because simply deleting and recreating the key without proper notification and impact analysis might delay response efforts. Rotation is a more structured Option D: This is correct because rotating the API key ensures that the compromised key is no longer valid. Notifying the administrator helps assess potential security impacts and plan further mitigation steps.

Topics

#API key management#key rotation#security incident response#cloud integration

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice