nerdexam
CrowdStrike

CCCS-203B · Question #174

You are tasked with ensuring that CrowdStrike can effectively assess container images in your environment. Which of the following actions should you take to allow image assessment without interruption

The correct answer is B. Add CrowdStrike IP addresses to the registry allowlist.. Option A: CrowdStrike doesn't use elevated privileges to bypass allowlist requirements. Its integration depends on proper allowlist configuration. This answer reflects a misunderstanding of CrowdStrike's operational principles. Option B: CrowdStrike's image assessment service int

Container Image Assessment

Question

You are tasked with ensuring that CrowdStrike can effectively assess container images in your environment. Which of the following actions should you take to allow image assessment without interruption?

Options

  • AConfigure CrowdStrike to bypass allowlist requirements via elevated privileges.
  • BAdd CrowdStrike IP addresses to the registry allowlist.
  • CAdd container image tags associated with CrowdStrike to the allowlist.
  • DDisable the firewall on all nodes where container images are stored.

How the community answered

(27 responses)
  • B
    96% (26)
  • C
    4% (1)

Explanation

Option A: CrowdStrike doesn't use elevated privileges to bypass allowlist requirements. Its integration depends on proper allowlist configuration. This answer reflects a misunderstanding of CrowdStrike's operational principles. Option B: CrowdStrike's image assessment service interacts with your container registry to scan images for vulnerabilities. For this process to occur without interruptions, the IP addresses used by CrowdStrike must be allowed through your registry's network controls. This ensures that CrowdStrike's scanning traffic isn't blocked, allowing seamless integration and accurate scanning. Option C: Allowlisting tags doesn't enable network communication. CrowdStrike relies on its IP addresses being allowlisted, not image tags. Misinterpreting tags as a network control mechanism would result in failed scans. Option D: Disabling the firewall is a poor security practice. Firewalls are critical for securing nodes and preventing unauthorized access. Instead, the proper approach is to selectively allow CrowdStrike IPs through the firewall or allowlist them in the registry configuration.

Topics

#Image Assessment#Registry Allowlist#IP Allowlisting#Container Registry Access

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice