nerdexam
CrowdStrike

CCCS-203B · Question #120

An organization using CrowdStrike Falcon Cloud Security wants to exclude specific resources from automated security scans to reduce false positives and optimize scan efficiency. Which of the…

The correct answer is C. Define exclusion rules in the Falcon Cloud Security dashboard, specifying resource tags. Option A: While IAM policies can restrict access to certain cloud resources, they are not the correct method for configuring scan exclusions in Falcon Cloud Security. Using IAM policies in this way could inadvertently prevent security visibility rather than properly configuring…

Cloud Security Posture Management

Question

An organization using CrowdStrike Falcon Cloud Security wants to exclude specific resources from automated security scans to reduce false positives and optimize scan efficiency. Which of the following is the correct method for configuring cloud security scan exclusion settings?

Options

  • AConfigure IAM policies to block Falcon Cloud Security from accessing specific cloud storage
  • BModify the Falcon agent's configuration file on each cloud workload to disable scanning for
  • CDefine exclusion rules in the Falcon Cloud Security dashboard, specifying resource tags,
  • DUse Kubernetes pod security policies (PSP) to prevent Falcon Cloud Security from scanning

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    80% (16)
  • D
    5% (1)

Explanation

Option A: While IAM policies can restrict access to certain cloud resources, they are not the correct method for configuring scan exclusions in Falcon Cloud Security. Using IAM policies in this way could inadvertently prevent security visibility rather than properly configuring exclusions. Option B: The Falcon agent is primarily used for endpoint and workload protection but does not control Falcon cloud security scans, which operate at the cloud account level. Configuring agent settings would not prevent cloud security scans from occurring. Option C: Falcon Cloud Security allows administrators to configure scan exclusions through the Falcon console, where they can define rules based on resource tags, cloud accounts, or regions. This ensures that security scans avoid designated resources while still protecting the overall cloud environment. Exclusions can help reduce noise from security alerts and improve efficiency in large-scale environments. Option D: Kubernetes Pod Security Policies (PSPs) control security settings for pods but do not affect Falcon Cloud Security's cloud-native scanning capabilities. PSPs define restrictions for running containers, such as preventing privileged access, but they do not manage scan

Topics

#scan exclusions#false positive reduction#Falcon dashboard#cloud resource tagging

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice