Free CrowdStrike CCCS-203b Actual Exam Questions - Question 2 Discussion

Question No. 2
After identifying inactive users using the CrowdStrike CIEM/Identity Analyzer, what is the most
appropriate action to mitigate risks associated with these accounts?
Select one option, then reveal solution.
US
SE
Sami E.
2026-02-11

Maybe B is better since it lets you catch any unexpected use or threat before deciding to delete or restore accounts, reducing risk without rushing. A and D feel too extreme without that monitoring step.

0
WU
Will U.
2026-02-10

Maybe C works too since it cuts off access but keeps everything ready if the user needs to be reactivated, avoiding any operational delays while managing risk.

0
OT
Omar T.
2026-01-28

C/D? Deactivating accounts (C) stops access but keeps the setup for easy reactivation, which might be useful. Immediate deletion (D) feels risky unless you’re 100% sure those accounts won’t be needed again.

0
JU
James U.
2026-01-23

Option B makes sense because disabling accounts temporarily limits risk without losing control immediately. Transferring permissions (A) could cause security issues by spreading access unnecessarily. Keeping roles after deactivation (C) might leave permissions hanging around, which isn’t ideal. Immediate deletion (D) could lead to problems if the account needs to be restored or checked later. So, temporarily disabling and monitoring is a balanced way to handle inactive users securely while keeping options open.

0
RO
Ryan O.
2026-01-21

It’s B, since immediate deletion (D) risks losing needed access if reactivation is required.

0
AX
Ali X.
2026-01-15

C/D? Deleting accounts right away (D) might be risky if they’re linked to important data or processes, so that feels too harsh. On the other hand, just deactivating but keeping roles (C) could leave permissions dangling without control. Temporarily disabling then monitoring, like B, seems safer overall to catch any unexpected use before making a final call. Transferring permissions (A) seems unrelated to risk mitigation here.

0
AX
Ali X.
2026-01-14

I think B makes the most sense—disabling first to see if anything weird happens before deleting or deactivating. Safer approach.

0