nerdexam
CrowdStrike

CCCS-203B · Question #269

During a review of the CrowdStrike Falcon asset inventory, you notice a legacy Windows XP device that is not running an endpoint protection solution. This asset has frequent outbound connections to…

The correct answer is D. Quarantine the device using Falcon's network containment feature and initiate a vulnerability. Option A: Even if the asset serves a legitimate purpose, ignoring it without addressing its risks leaves your environment exposed to potential exploits or lateral movement by attackers. Option B: Removing the asset from the inventory introduces blind spots in your monitoring…

Asset Management and Threat Response

Question

During a review of the CrowdStrike Falcon asset inventory, you notice a legacy Windows XP device that is not running an endpoint protection solution. This asset has frequent outbound connections to unrecognized external IPs. Which of the following is the best course of action to handle this risky asset?

Options

  • AIgnore the asset as it might be part of a legitimate business process.
  • BUninstall the device from the asset inventory to reduce noise in monitoring.
  • CImmediately block all outbound connections from this asset at the firewall.
  • DQuarantine the device using Falcon's network containment feature and initiate a vulnerability

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    10% (5)
  • D
    83% (40)

Explanation

Option A: Even if the asset serves a legitimate purpose, ignoring it without addressing its risks leaves your environment exposed to potential exploits or lateral movement by attackers. Option B: Removing the asset from the inventory introduces blind spots in your monitoring and doesn't address the security risks it poses. Option C: Blocking connections at the firewall addresses only part of the issue and doesn't resolve the inherent vulnerability of the device. The asset still requires further investigation and Option D: Legacy systems like Windows XP are inherently risky as they no longer receive security updates. Coupled with the lack of endpoint protection and suspicious outbound traffic, this asset poses a significant threat. Quarantining the device ensures it is isolated from the network while a vulnerability assessment identifies any further risks or malicious activity. This is a proactive and effective approach to mitigating the risk.

Topics

#legacy asset risk#network containment#vulnerability assessment#asset inventory

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice