nerdexam
CrowdStrike

CCCS-203B · Question #265

When configuring a cloud account with APIs for CrowdStrike Falcon, which permissions must the API client include?

The correct answer is D. Scoped permissions to access specific resources such as compute, identity, and logging services. Option A: Granting administrative tasks across all resources is excessive and violates the principle of least privilege. Scoped permissions specific to Falcon's needs are sufficient and more Option B: Unrestricted access to all API calls is unnecessary and introduces significant

Cloud Account Registration and Integration

Question

When configuring a cloud account with APIs for CrowdStrike Falcon, which permissions must the API client include?

Options

  • APermissions to perform administrative tasks across all resources within the cloud account.
  • BFull permissions for all API calls to ensure Falcon has unrestricted access.
  • CCustom permissions that only allow integration with third-party monitoring tools.
  • DScoped permissions to access specific resources such as compute, identity, and logging services

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    5% (2)
  • D
    86% (36)

Explanation

Option A: Granting administrative tasks across all resources is excessive and violates the principle of least privilege. Scoped permissions specific to Falcon's needs are sufficient and more Option B: Unrestricted access to all API calls is unnecessary and introduces significant security risks. Falcon's integration requires only specific permissions, not full administrative access. Option C: Permissions limited to third-party monitoring tools would exclude the necessary actions for Falcon to function properly, such as managing cloud configurations and detecting misconfigurations. Option D: Scoped permissions ensure Falcon has access to resources it needs (e.g., compute for workload monitoring, identity for user access logs, and logging services like CloudTrail). This approach balances functionality and security.

Topics

#API client permissions#scoped access#least privilege#cloud integration

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice