nerdexam
CrowdStrike

CCCS-203B · Question #268

When managing API clients and keys in the Falcon platform, what is the best practice to ensure security and operational integrity?

The correct answer is A. Rotate API keys regularly and delete unused keys. Option A: Regularly rotating API keys and deleting unused ones minimizes the risk of unauthorized access, ensuring operational security and compliance with best practices. Option B: Sharing API keys with multiple vendors is insecure and violates best practices. Each vendor…

Platform Administration

Question

When managing API clients and keys in the Falcon platform, what is the best practice to ensure security and operational integrity?

Options

  • ARotate API keys regularly and delete unused keys.
  • BShare API keys with all third-party vendors for easy integration.
  • CUse one API key for all integrations to reduce complexity in management.
  • DGrant API keys full access to all modules for flexibility and ease of use.

How the community answered

(39 responses)
  • A
    87% (34)
  • B
    8% (3)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Option A: Regularly rotating API keys and deleting unused ones minimizes the risk of unauthorized access, ensuring operational security and compliance with best practices. Option B: Sharing API keys with multiple vendors is insecure and violates best practices. Each vendor should have unique keys with specific permissions. Option C: Using a single API key for multiple integrations increases the risk of compromise and makes it harder to isolate issues or rotate keys when needed. Option D: Granting full access unnecessarily increases the attack surface and violates the principle of least privilege, which is essential for security.

Topics

#API key rotation#security best practices#API management#least privilege

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice