CCCS-203B · Question #305
Your organization has identified several accounts that do not have Multi-Factor Authentication (MFA) enabled, using CrowdStrike's CIEM. Which of the following actions would be the most effective…
The correct answer is C. Use CIEM to enforce MFA policies across all accounts. Option A: Restricting permissions to "read-only" does not address the core issue of MFA enforcement. These accounts remain vulnerable to unauthorized access, especially if they are Option B: Monitoring unusual activity is a reactive measure and does not mitigate the risk posed…
Question
Your organization has identified several accounts that do not have Multi-Factor Authentication (MFA) enabled, using CrowdStrike's CIEM. Which of the following actions would be the most effective first step to mitigate the security risk associated with these accounts?
Options
- AAssign "read-only" permissions to non-MFA accounts to limit their impact.
- BSet up an alert system to monitor non-MFA accounts for unusual activity.
- CUse CIEM to enforce MFA policies across all accounts.
- DDisable all non-MFA accounts immediately to prevent unauthorized access.
How the community answered
(67 responses)- A3% (2)
- B7% (5)
- C73% (49)
- D16% (11)
Explanation
Option A: Restricting permissions to "read-only" does not address the core issue of MFA enforcement. These accounts remain vulnerable to unauthorized access, especially if they are Option B: Monitoring unusual activity is a reactive measure and does not mitigate the risk posed by non-MFA accounts. Proactively enforcing MFA policies is a better strategy for reducing Option C: Using CIEM to enforce MFA policies ensures a consistent and automated approach to improving account security. This method reduces the likelihood of human error and applies a scalable solution to protect all accounts, aligning with best practices for cloud identity Option D: While disabling non-MFA accounts might reduce risk temporarily, it can disrupt business operations. A more measured approach, such as enforcing MFA, is preferable to balance security and functionality.
Topics
Community Discussion
No community discussion yet for this question.