nerdexam
CrowdStrike

CCCS-203B · Question #76

CCCS-203B Question #76: Real Exam Question with Answer & Explanation

The correct answer is B. A non-administrative user suddenly escalates privileges and modifies cloud security policies.. Option A: Developers accessing repositories during normal hours is expected behavior, unless there are signs of unauthorized activity. Option B: Privilege escalation and modification of security policies by a non-administrative user is a strong indicator of risk. This could sugge

Question

A security administrator using CrowdStrike Falcon wants to audit user account activity to identify potential risks associated with compromised or overprivileged accounts. Which of the following activities would be the strongest indicator of a security risk?

Options

  • AA developer accesses a cloud resource repository during standard working hours.
  • BA non-administrative user suddenly escalates privileges and modifies cloud security policies.
  • CA user requests temporary access to a sensitive database as part of an approved change request.
  • DA user logs in from a new geographic location for the first time but performs no unusual actions.

Explanation

Option A: Developers accessing repositories during normal hours is expected behavior, unless there are signs of unauthorized activity. Option B: Privilege escalation and modification of security policies by a non-administrative user is a strong indicator of risk. This could suggest account compromise, insider threats, or policy violations, requiring immediate investigation. Option C: Temporary access requests for databases that follow approval workflows do not indicate unauthorized activity or risk. Option D: A new geographic login might warrant further monitoring, but without additional suspicious actions, it is not a definitive security risk.

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice