CCCS-203B · Question #209
An organization has deployed CrowdStrike Falcon on their cloud workloads, but they notice that real-time detection and blocking are not functioning as expected. Upon reviewing the deployment, they…
The correct answer is C. The Falcon Container Sensor was installed without enabling workload protection policies. Option A: While some older versions of Docker may have compatibility issues, most modern Docker versions are supported by CrowdStrike Falcon. The issue is more likely a misconfiguration than a compatibility problem. Option B: While a "monitor-only" policy can prevent blocking…
Question
An organization has deployed CrowdStrike Falcon on their cloud workloads, but they notice that real-time detection and blocking are not functioning as expected. Upon reviewing the deployment, they identify a configuration oversight. Which of the following is the most likely reason that runtime protection is not working?
Options
- AThe container runtime is using an unsupported version of Docker.
- BThe cloud workload protection policies are configured to monitor but not block threats.
- CThe Falcon Container Sensor was installed without enabling workload protection policies.
- DThe Falcon sensor logs indicate no active threats were detected, meaning the deployment is
How the community answered
(46 responses)- A4% (2)
- B13% (6)
- C76% (35)
- D7% (3)
Explanation
Option A: While some older versions of Docker may have compatibility issues, most modern Docker versions are supported by CrowdStrike Falcon. The issue is more likely a misconfiguration than a compatibility problem. Option B: While a "monitor-only" policy can prevent blocking, it does not explain why real-time detection is not functioning. The absence of protection is likely due to a broader misconfiguration. Option C: Even if the Falcon Sensor is installed correctly, runtime protection requires active security policies. If these policies are missing or misconfigured, the sensor will not enforce security actions, leading to ineffective threat prevention. Option D: The absence of detected threats does not confirm that protection is working. It is possible that policies are misconfigured, and malicious activity is going unnoticed.
Topics
Community Discussion
No community discussion yet for this question.