CCCS-203B · Question #261
What is the primary function of the Cloud Infrastructure Entitlement Manager (CIEM) in identifying accounts with unnecessary access privileges?
The correct answer is C. To analyze permissions and identify accounts with excessive or unused access rights. Option A: Encryption key management is a distinct function typically handled by Key Management Services (KMS). CIEM addresses access and entitlement, not cryptographic Option B: CIEM is not primarily used for account provisioning. Its goal is to analyze and optimize existing…
Question
What is the primary function of the Cloud Infrastructure Entitlement Manager (CIEM) in identifying accounts with unnecessary access privileges?
Options
- ATo manage encryption keys for securing sensitive cloud data.
- BTo provision new accounts with baseline privileges automatically.
- CTo analyze permissions and identify accounts with excessive or unused access rights.
- DTo enforce multi-factor authentication (MFA) across all cloud accounts.
How the community answered
(69 responses)- A1% (1)
- B3% (2)
- C94% (65)
- D1% (1)
Explanation
Option A: Encryption key management is a distinct function typically handled by Key Management Services (KMS). CIEM addresses access and entitlement, not cryptographic Option B: CIEM is not primarily used for account provisioning. Its goal is to analyze and optimize existing permissions rather than create new accounts or manage initial privilege assignments. Option C: CIEM solutions, such as Identity Analyzer, are designed to evaluate user and service account permissions, highlighting instances where access exceeds what is necessary. This helps prevent potential privilege abuse or misconfigurations that could lead to security vulnerabilities. Option D: While enforcing MFA is a critical security measure, it is not the primary function of CIEM. CIEM focuses on identifying and managing access entitlements to minimize unnecessary privileges. MFA falls under identity security measures but does not directly address unnecessary
Topics
Community Discussion
No community discussion yet for this question.