CCCS-203B · Question #266
An organization's security team is using CrowdStrike Falcon Cloud Security to monitor their cloud infrastructure. During an assessment, they discover that some workloads are not generating security…
The correct answer is B. The Falcon sensor was installed on cloud instances but lacks the required permissions to collect. Option A: While internet access is necessary for cloud-based management features (e.g., reporting and policy updates), Falcon sensors can still perform local analysis and generate alerts based on predefined policies. The lack of alerts is more likely due to a permissions…
Question
An organization's security team is using CrowdStrike Falcon Cloud Security to monitor their cloud infrastructure. During an assessment, they discover that some workloads are not generating security alerts, even though they should be monitored under the configured security policies. Which of the following is the most likely indicator of misconfiguration (IOM) that could explain this issue?
Options
- AThe cloud instances are running in a Virtual Private Cloud (VPC) without internet access.
- BThe Falcon sensor was installed on cloud instances but lacks the required permissions to collect
- CThe security policies applied in Falcon Cloud Security are too strict, which prevents alert
- DThe Falcon console is displaying normal operational logs, so there are no security concerns.
How the community answered
(24 responses)- A4% (1)
- B79% (19)
- C4% (1)
- D13% (3)
Explanation
Option A: While internet access is necessary for cloud-based management features (e.g., reporting and policy updates), Falcon sensors can still perform local analysis and generate alerts based on predefined policies. The lack of alerts is more likely due to a permissions misconfiguration than a network restriction. Option B: The Falcon sensor requires specific permissions to collect logs, analyze behavior, and report findings to the Falcon console. If permissions are misconfigured or missing, the sensor may fail to generate security alerts, leading to undetected threats. Option C: Strict security policies do not prevent alerts. Instead, they may lead to increased logging and alerting. If no alerts are being generated, it is more likely a configuration or permissions issue rather than an overly strict policy. Option D: Normal logs do not necessarily indicate a secure environment. If Falcon is not detecting threats due to misconfigurations, this could create a false sense of security. Security teams should always validate configurations rather than assuming security based on system logs alone.
Topics
Community Discussion
No community discussion yet for this question.