CCCS-203B · Question #91
After identifying inactive users using the CrowdStrike CIEM/Identity Analyzer, what is the most appropriate action to mitigate risks associated with these accounts?
The correct answer is B. Temporarily disable inactive accounts and monitor for unexpected activity before permanent. Option A: Transferring permissions without a clear business need or appropriate analysis can lead to excessive privilege assignments and violate the principle of least privilege, increasing the risk of insider threats or accidental misuse. Option B: Temporarily disabling inactive
Question
After identifying inactive users using the CrowdStrike CIEM/Identity Analyzer, what is the most appropriate action to mitigate risks associated with these accounts?
Options
- ATransfer the permissions of inactive accounts to active users for operational efficiency.
- BTemporarily disable inactive accounts and monitor for unexpected activity before permanent
- CDeactivate inactive accounts but retain their associated roles and permissions.
- DImmediately delete all inactive user accounts.
How the community answered
(47 responses)- A4% (2)
- B77% (36)
- C13% (6)
- D6% (3)
Explanation
Option A: Transferring permissions without a clear business need or appropriate analysis can lead to excessive privilege assignments and violate the principle of least privilege, increasing the risk of insider threats or accidental misuse. Option B: Temporarily disabling inactive accounts allows organizations to verify whether the accounts are genuinely no longer in use while preventing immediate security risks. Monitoring for unexpected activity during the temporary disablement phase helps identify potential misuse or ongoing necessity of the account, ensuring informed decisions about deactivation or deletion. Option C: Deactivating accounts without addressing roles and permissions still poses a security risk. Inactive accounts with retained permissions can be re-enabled or misused inappropriately. Option D: While deleting inactive accounts removes potential attack vectors, this approach is risky without prior analysis. Some accounts may be needed for legacy systems or auditing purposes, leading to operational disruption.
Topics
Community Discussion
No community discussion yet for this question.