nerdexam
CrowdStrike

CCCS-203B · Question #91

After identifying inactive users using the CrowdStrike CIEM/Identity Analyzer, what is the most appropriate action to mitigate risks associated with these accounts?

The correct answer is B. Temporarily disable inactive accounts and monitor for unexpected activity before permanent. Option A: Transferring permissions without a clear business need or appropriate analysis can lead to excessive privilege assignments and violate the principle of least privilege, increasing the risk of insider threats or accidental misuse. Option B: Temporarily disabling inactive

Cloud Identity and Entitlement Management (CIEM)

Question

After identifying inactive users using the CrowdStrike CIEM/Identity Analyzer, what is the most appropriate action to mitigate risks associated with these accounts?

Options

  • ATransfer the permissions of inactive accounts to active users for operational efficiency.
  • BTemporarily disable inactive accounts and monitor for unexpected activity before permanent
  • CDeactivate inactive accounts but retain their associated roles and permissions.
  • DImmediately delete all inactive user accounts.

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    77% (36)
  • C
    13% (6)
  • D
    6% (3)

Explanation

Option A: Transferring permissions without a clear business need or appropriate analysis can lead to excessive privilege assignments and violate the principle of least privilege, increasing the risk of insider threats or accidental misuse. Option B: Temporarily disabling inactive accounts allows organizations to verify whether the accounts are genuinely no longer in use while preventing immediate security risks. Monitoring for unexpected activity during the temporary disablement phase helps identify potential misuse or ongoing necessity of the account, ensuring informed decisions about deactivation or deletion. Option C: Deactivating accounts without addressing roles and permissions still poses a security risk. Inactive accounts with retained permissions can be re-enabled or misused inappropriately. Option D: While deleting inactive accounts removes potential attack vectors, this approach is risky without prior analysis. Some accounts may be needed for legacy systems or auditing purposes, leading to operational disruption.

Topics

#inactive accounts#CIEM#account lifecycle management#identity risk mitigation

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice