CCCS-203B · Question #93
After identifying excessive permissions and missing MFA in IAM configurations, which remediation strategy is most aligned with CrowdStrike CIEM's recommendations?
The correct answer is C. Enable MFA and implement least privilege access policies for the flagged accounts. Option A: Deleting accounts without assessing their purpose could lead to operational disruptions, especially if service accounts or critical roles are affected. CIEM focuses on remediation, not immediate deletion. Option B: Revoking all permissions is overly disruptive and…
Question
After identifying excessive permissions and missing MFA in IAM configurations, which remediation strategy is most aligned with CrowdStrike CIEM's recommendations?
Options
- ADelete all accounts flagged by CIEM's Identity Analyzer.
- BRevoke all permissions from the identified accounts.
- CEnable MFA and implement least privilege access policies for the flagged accounts.
- DTransfer ownership of flagged accounts to a different administrator.
How the community answered
(57 responses)- A11% (6)
- B2% (1)
- C82% (47)
- D5% (3)
Explanation
Option A: Deleting accounts without assessing their purpose could lead to operational disruptions, especially if service accounts or critical roles are affected. CIEM focuses on remediation, not immediate deletion. Option B: Revoking all permissions is overly disruptive and impractical. Instead, permissions should be adjusted based on the principle of least privilege to allow users to perform their roles Option C: CIEM emphasizes the principle of least privilege and the enforcement of MFA as core security practices. Adjusting permissions to align with job roles and enabling MFA significantly reduces the attack surface and prevents unauthorized access. Option D: Transferring ownership does not address the underlying issue of excessive permissions or missing MFA. It is a superficial action that leaves the security risks unresolved.
Topics
Community Discussion
No community discussion yet for this question.