nerdexam
CrowdStrike

CCCS-203B · Question #70

You are tasked with assigning policies in a cloud environment using CrowdStrike's Identity Analyzer. Which of the following configurations aligns best with the principle of least privilege?

The correct answer is D. Creating role-based policies that restrict access to only the services and actions necessary for. Option A: A one-size-fits-all approach ignores the unique requirements of different roles and leads to over-permissioning or under-permissioning, both of which are undesirable from a security Option B: Granting administrative privileges universally undermines security and…

Cloud Identity and Access Management

Question

You are tasked with assigning policies in a cloud environment using CrowdStrike's Identity Analyzer. Which of the following configurations aligns best with the principle of least privilege?

Options

  • AAssigning identical policies to all users regardless of their roles or responsibilities.
  • BGranting unrestricted administrative privileges to all roles to ensure productivity.
  • CAssigning a single, broad policy to grant all users access to all cloud services.
  • DCreating role-based policies that restrict access to only the services and actions necessary for

How the community answered

(18 responses)
  • C
    6% (1)
  • D
    94% (17)

Explanation

Option A: A one-size-fits-all approach ignores the unique requirements of different roles and leads to over-permissioning or under-permissioning, both of which are undesirable from a security Option B: Granting administrative privileges universally undermines security and increases the likelihood of human error or exploitation. Only specific roles requiring administrative capabilities should have such access. Option C: Broad policies that grant universal access violate the principle of least privilege. They expose the environment to unnecessary risks, such as unauthorized data access or resource Option D: This approach follows the principle of least privilege, ensuring users and roles have access only to the resources and actions required for their responsibilities. This minimizes the attack surface, reduces the risk of accidental or malicious misuse, and adheres to best practices in identity and access management.

Topics

#least privilege#RBAC#CIEM#access policies

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice