nerdexam
CrowdStrike

CCCS-203B · Question #209

An organization has deployed CrowdStrike Falcon on their cloud workloads, but they notice that real-time detection and blocking are not functioning as expected. Upon reviewing the deployment, they…

The correct answer is C. The Falcon Container Sensor was installed without enabling workload protection policies. Option A: While some older versions of Docker may have compatibility issues, most modern Docker versions are supported by CrowdStrike Falcon. The issue is more likely a misconfiguration than a compatibility problem. Option B: While a "monitor-only" policy can prevent blocking…

Cloud Workload Protection

Question

An organization has deployed CrowdStrike Falcon on their cloud workloads, but they notice that real-time detection and blocking are not functioning as expected. Upon reviewing the deployment, they identify a configuration oversight. Which of the following is the most likely reason that runtime protection is not working?

Options

  • AThe container runtime is using an unsupported version of Docker.
  • BThe cloud workload protection policies are configured to monitor but not block threats.
  • CThe Falcon Container Sensor was installed without enabling workload protection policies.
  • DThe Falcon sensor logs indicate no active threats were detected, meaning the deployment is

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    13% (6)
  • C
    76% (35)
  • D
    7% (3)

Explanation

Option A: While some older versions of Docker may have compatibility issues, most modern Docker versions are supported by CrowdStrike Falcon. The issue is more likely a misconfiguration than a compatibility problem. Option B: While a "monitor-only" policy can prevent blocking, it does not explain why real-time detection is not functioning. The absence of protection is likely due to a broader misconfiguration. Option C: Even if the Falcon Sensor is installed correctly, runtime protection requires active security policies. If these policies are missing or misconfigured, the sensor will not enforce security actions, leading to ineffective threat prevention. Option D: The absence of detected threats does not confirm that protection is working. It is possible that policies are misconfigured, and malicious activity is going unnoticed.

Topics

#runtime protection#Falcon sensor#workload protection policy#configuration

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice