CCCS-203B · Question #3
You are tasked with editing a cloud security posture policy in the CrowdStrike Falcon platform to ensure that all S3 buckets in your AWS environment are encrypted. Which of the following changes…
The correct answer is D. Configure a rule in the cloud security posture policy to detect unencrypted S3 buckets and set the. Option A: Disabling versioning affects data retention and rollback capabilities but has no impact on encryption requirements. Option B: Logging bucket access provides audit trails but does not ensure encryption. It serves a different purpose, primarily for compliance and…
Question
You are tasked with editing a cloud security posture policy in the CrowdStrike Falcon platform to ensure that all S3 buckets in your AWS environment are encrypted. Which of the following changes should you make to achieve this goal?
Options
- ADisable versioning on S3 buckets in the cloud security posture policy.
- BEnable the "Log Bucket Access" feature to track all access attempts.
- CEnable the "Restrict Public Access" option under the S3 policy settings.
- DConfigure a rule in the cloud security posture policy to detect unencrypted S3 buckets and set the
How the community answered
(24 responses)- A4% (1)
- B17% (4)
- C4% (1)
- D75% (18)
Explanation
Option A: Disabling versioning affects data retention and rollback capabilities but has no impact on encryption requirements. Option B: Logging bucket access provides audit trails but does not ensure encryption. It serves a different purpose, primarily for compliance and monitoring. Option C: Restricting public access enhances security but does not enforce encryption on S3 This option is unrelated to encryption requirements. Option D: To ensure S3 bucket encryption, you must create a rule within the cloud security posture policy that identifies unencrypted S3 buckets. Setting the action to "Alert" notifies administrators of non-compliant buckets while allowing them to address issues. This approach directly targets encryption settings, aligning with cloud security best practices.
Topics
Community Discussion
No community discussion yet for this question.