CCCS-203B · Question #85
A healthcare organization is required to comply with HIPAA regulations and is using CrowdStrike Falcon to monitor and enforce security rules in its AWS, Azure, and Google Cloud environments. Which…
The correct answer is B. Implement adaptive security rules that leverage behavioral analytics and threat intelligence. Option A: Disabling logging and monitoring violates HIPAA compliance and makes it impossible to detect security incidents. Cloud security requires continuous monitoring, audit logging, and alerting to ensure compliance and threat mitigation. Option B: Adaptive security rules…
Question
A healthcare organization is required to comply with HIPAA regulations and is using CrowdStrike Falcon to monitor and enforce security rules in its AWS, Azure, and Google Cloud environments. Which security rule implementation is most effective in ensuring compliance while mitigating threats?
Options
- ADisable logging and monitoring to minimize storage costs.
- BImplement adaptive security rules that leverage behavioral analytics and threat intelligence
- CUse default security group settings from the cloud providers.
- DEnable strict allow-all policies to reduce operational complexity.
How the community answered
(21 responses)- A24% (5)
- B62% (13)
- C10% (2)
- D5% (1)
Explanation
Option A: Disabling logging and monitoring violates HIPAA compliance and makes it impossible to detect security incidents. Cloud security requires continuous monitoring, audit logging, and alerting to ensure compliance and threat mitigation. Option B: Adaptive security rules using behavioral analytics and threat intelligence allow for proactive threat detection and dynamic policy enforcement, ensuring both security and compliance. This method prevents anomalies and unauthorized access without disrupting legitimate operations. Option C: Default security group settings from cloud providers are often overly permissive. These must be hardened with least privilege rules to prevent unauthorized access and data exposure. Option D: An allow-all policy is a major security risk as it removes all access controls, making cloud resources vulnerable to unauthorized access and potential data breaches, violating HIPAA
Topics
Community Discussion
No community discussion yet for this question.