CCCS-203B · Question #294
Which of the following scenarios represents a security risk that CrowdStrike Identity Analyzer (CIEM) is designed to identify and address?
The correct answer is C. An IAM role with permissions to delete all cloud resources is assigned to multiple non-human. Option A: Allowing inbound traffic on port 443 (HTTPS) is a standard practice for secure web services. While this could be a misconfiguration if unnecessary, it falls under network security rather than identity management, which is the focus of CIEM. Option B: Concurrency…
Question
Which of the following scenarios represents a security risk that CrowdStrike Identity Analyzer (CIEM) is designed to identify and address?
Options
- AA network security group is configured to allow inbound traffic on port 443
- BA serverless function has a concurrency limit set to 100 executions
- CAn IAM role with permissions to delete all cloud resources is assigned to multiple non-human
- DAn encrypted storage bucket is accessed by an authorized application
How the community answered
(26 responses)- A4% (1)
- B4% (1)
- C81% (21)
- D12% (3)
Explanation
Option A: Allowing inbound traffic on port 443 (HTTPS) is a standard practice for secure web services. While this could be a misconfiguration if unnecessary, it falls under network security rather than identity management, which is the focus of CIEM. Option B: Concurrency settings relate to resource performance and scalability, not identity or entitlement management. CIEM does not monitor or manage execution limits for serverless Option C: CIEM is specifically designed to detect and analyze overly permissive roles and identities, particularly when sensitive permissions (like resource deletion) are assigned to multiple non-human identities. This scenario poses a significant security risk if those identities are compromised or misused. Option D: This is an expected and secure behavior when proper access policies are in place. CIEM would not flag this as an issue since the access is authorized and aligns with standard operational practices.
Topics
Community Discussion
No community discussion yet for this question.