nerdexam
CrowdStrike

CCCS-203B · Question #88

During an audit of your organization's CrowdStrike Identity Analyzer configuration, you find several policies related to cloud service access. Which of the following represents a misconfiguration…

The correct answer is C. A policy that allows all users to create and delete resources in production environments. Option A: Denying access to sensitive resources for unauthorized roles enhances security and ensures that users cannot access resources they are not entitled to. Option B: Read-only access aligns with least privilege, ensuring analysts can view data without modifying it. This…

Cloud Identity and Entitlement Management (CIEM)

Question

During an audit of your organization's CrowdStrike Identity Analyzer configuration, you find several policies related to cloud service access. Which of the following represents a misconfiguration that needs immediate remediation?

Options

  • AA policy that explicitly denies access to sensitive resources for unauthorized roles.
  • BA policy that provides read-only access to database services for analysts.
  • CA policy that allows all users to create and delete resources in production environments.
  • DA policy that provides specific permissions for developers to deploy services within staging

How the community answered

(39 responses)
  • A
    26% (10)
  • B
    15% (6)
  • C
    51% (20)
  • D
    8% (3)

Explanation

Option A: Denying access to sensitive resources for unauthorized roles enhances security and ensures that users cannot access resources they are not entitled to. Option B: Read-only access aligns with least privilege, ensuring analysts can view data without modifying it. This is a correctly configured policy. Option C: This misconfiguration grants excessive privileges to all users, violating the principle of least privilege and increasing the risk of accidental or intentional misuse. Access to production environments should be tightly controlled and limited to specific, authorized roles. Option D: Granting developers permissions tailored to their role in a non-production environment aligns with best practices and does not pose a security risk.

Topics

#IAM policy misconfiguration#Identity Analyzer#production access control#policy audit

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice