CCCS-203B · Question #30
You are reviewing user accounts in your organization using the CrowdStrike CIEM/Identity Analyzer. Which of the following scenarios represents the correct method to identify an inactive user?
The correct answer is A. A user who has no recorded login activity for the past 90 days and has no active API tokens. Option A: This scenario aligns with the definition of an inactive user. A lack of login activity combined with the absence of active API tokens indicates that the user account is not currently in use, making it a candidate for review or deactivation. CIEM tools are designed to…
Question
You are reviewing user accounts in your organization using the CrowdStrike CIEM/Identity Analyzer. Which of the following scenarios represents the correct method to identify an inactive user?
Options
- AA user who has no recorded login activity for the past 90 days and has no active API tokens.
- BA user who recently logged in and modified IAM policies but has minimal activity in other
- CA user who has logged in twice in the past week but has not used any IAM role or resource
- DA user with no logins or API activity in the last 30 days but with active IAM roles assigned.
How the community answered
(64 responses)- A77% (49)
- B6% (4)
- C13% (8)
- D5% (3)
Explanation
Option A: This scenario aligns with the definition of an inactive user. A lack of login activity combined with the absence of active API tokens indicates that the user account is not currently in use, making it a candidate for review or deactivation. CIEM tools are designed to highlight such accounts to reduce unnecessary exposure. Option B: Modifying IAM policies is a critical activity, and the recent login further indicates the account is active. Minimal resource usage doesn't qualify the user as inactive. Option C: Regular logins indicate activity. Even if IAM roles or resources are not utilized, the login behavior demonstrates some level of engagement, so the user is not considered inactive. Option D: While the user shows inactivity, the presence of active IAM roles suggests potential risk if roles are misused. This might warrant review but doesn't definitively qualify the account as inactive until a longer inactivity period is confirmed.
Topics
Community Discussion
No community discussion yet for this question.