CCCS-203B · Question #292
Which of the following automated remediation actions can CrowdStrike initiate within AWS when a threat is detected?
The correct answer is A. Restricting outbound traffic from a compromised instance by updating the Security Group rules. Option A: Automated remediation can include modifying Security Group rules to block outbound traffic, effectively containing a compromised instance and preventing data exfiltration. Option B: Deleting IAM users is a drastic action that could disrupt legitimate operations…
Question
Which of the following automated remediation actions can CrowdStrike initiate within AWS when a threat is detected?
Options
- ARestricting outbound traffic from a compromised instance by updating the Security Group rules.
- BDeleting all IAM users associated with the compromised account.
- CAutomatically encrypting all EBS volumes in the AWS account.
- DTriggering a manual review of security logs by the AWS administrator.
How the community answered
(37 responses)- A92% (34)
- B3% (1)
- C5% (2)
Explanation
Option A: Automated remediation can include modifying Security Group rules to block outbound traffic, effectively containing a compromised instance and preventing data exfiltration. Option B: Deleting IAM users is a drastic action that could disrupt legitimate operations. Instead, automated remediation focuses on targeted containment, such as disabling compromised Option C: Encryption is a preventive measure, not a remediation action. While encryption enhances security, it does not address active threats detected by CrowdStrike. Option D: While log reviews are essential for analysis, they are not automated remediation actions. CrowdStrike automates responses like containment and traffic restriction, not manual
Topics
Community Discussion
No community discussion yet for this question.