CrowdStrike
CCCS-203B · Question #76
A security administrator using CrowdStrike Falcon wants to audit user account activity to identify potential risks associated with compromised or overprivileged accounts. Which of the following activi
Sign in or unlock CCCS-203B to reveal the answer and full explanation for question #76. The question stem and answer options stay visible for context.
Cloud Identity and Access Management
Question
A security administrator using CrowdStrike Falcon wants to audit user account activity to identify potential risks associated with compromised or overprivileged accounts. Which of the following activities would be the strongest indicator of a security risk?
Options
- AA developer accesses a cloud resource repository during standard working hours.
- BA non-administrative user suddenly escalates privileges and modifies cloud security policies.
- CA user requests temporary access to a sensitive database as part of an approved change request.
- DA user logs in from a new geographic location for the first time but performs no unusual actions.
Unlock CCCS-203B to see the answer
You've previewed enough free CCCS-203B questions. Unlock CCCS-203B for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#privilege escalation#user activity audit#security risk indicators#account compromise