nerdexam
CrowdStrike

CCCS-203B · Question #8

A security engineer is conducting a review of cloud security controls within an AWS environment protected by CrowdStrike Falcon. During the evaluation, the engineer identifies that an attacker could g

Sign in or unlock CCCS-203B to reveal the answer and full explanation for question #8. The question stem and answer options stay visible for context.

Cloud Identity and Access Management

Question

A security engineer is conducting a review of cloud security controls within an AWS environment protected by CrowdStrike Falcon. During the evaluation, the engineer identifies that an attacker could gain elevated permissions through misconfigured IAM policies. Which of the following is the most likely misconfiguration leading to this high-risk practice?

Options

  • AThe Falcon sensor is installed in detection mode rather than prevention mode.
  • BThe security group associated with the instance has inbound SSH access restricted to a specific IP
  • CAn IAM policy grants Administrator Access privileges to an EC2 instance profile.
  • DThe cloud environment uses Multi-Factor Authentication (MFA) for privileged accounts.

Unlock CCCS-203B to see the answer

You've previewed enough free CCCS-203B questions. Unlock CCCS-203B for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM misconfiguration#privilege escalation#EC2 instance profile#AWS IAM
Full CCCS-203B Practice