CCCS-203B · Question #20
When editing an existing image assessment policy in Falcon Cloud Security, what should you prioritize to minimize disruptions to the development workflow?
The correct answer is D. Review and validate any exclusions to ensure they are still relevant and justified.. Option A: Policies should be tested in an audit-only mode or a controlled environment to ensure they do not disrupt workflows or block legitimate activities. Option B: While disabling exclusions might improve security, it can also disrupt legitimate workflows, leading to operatio
Question
When editing an existing image assessment policy in Falcon Cloud Security, what should you prioritize to minimize disruptions to the development workflow?
Options
- AApply the updated policy immediately without testing to enforce changes quickly.
- BDisable all existing exclusions to ensure maximum security coverage.
- CCreate broad rules that apply to all images regardless of their origin or purpose.
- DReview and validate any exclusions to ensure they are still relevant and justified.
How the community answered
(14 responses)- A7% (1)
- B14% (2)
- C36% (5)
- D43% (6)
Explanation
Option A: Policies should be tested in an audit-only mode or a controlled environment to ensure they do not disrupt workflows or block legitimate activities. Option B: While disabling exclusions might improve security, it can also disrupt legitimate workflows, leading to operational inefficiencies and developer frustration. Option C: Broad rules can cause unnecessary noise and block legitimate activities. Image assessment policies should be as granular as possible to target specific risks. Option D: Exclusions are necessary to prevent unnecessary alerts or blocks, but they must be reviewed regularly to ensure they remain relevant. Overly permissive exclusions can weaken security, while irrelevant exclusions can cause unnecessary complexity. Validating exclusions helps maintain a balance between security and operational efficiency.
Topics
Community Discussion
No community discussion yet for this question.