nerdexam
CrowdStrike

CCCS-203B · Question #28

CCCS-203B Question #28: Real Exam Question with Answer & Explanation

The correct answer is B. Investigate the ownership of the assets, validate their necessity, and enforce security policies or. Option A: Immediately deleting assets without investigation can cause disruptions if they are in use by critical services. Verification is essential before taking action. Option B: Unmanaged public-facing assets pose a significant security risk. The best practice is to identify o

Question

A security engineer is conducting an asset discovery assessment using CrowdStrike Falcon Cloud Security and finds several public-facing cloud resources that are not listed in the organization's asset inventory. Which of the following is the most appropriate action to take first?

Options

  • AImmediately delete the assets to prevent unauthorized access and remove them from the cloud
  • BInvestigate the ownership of the assets, validate their necessity, and enforce security policies or
  • CEnable network segmentation to prevent unauthorized access while continuing normal operations.
  • DRestrict outbound traffic from these assets using firewall rules, ensuring they cannot communicate

Explanation

Option A: Immediately deleting assets without investigation can cause disruptions if they are in use by critical services. Verification is essential before taking action. Option B: Unmanaged public-facing assets pose a significant security risk. The best practice is to identify ownership, assess their legitimacy, and either enforce security policies or decommission them if unnecessary. Shadow IT, forgotten deployments, or misconfigured assets can all lead to Option C: Network segmentation can limit exposure, but it does not address the root cause--why these assets exist and whether they are necessary or unauthorized. Option D: Restricting outbound traffic may reduce risk, but it does not address the issue of unmanaged public exposure. Attackers could still exploit misconfigurations or known vulnerabilities on these assets.

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice