nerdexam
CrowdStrike

CCCS-203B · Question #229

An organization uses a private container registry protected by strict access controls. To enable CrowdStrike to perform image assessment, what must the organization do?

The correct answer is A. Add CrowdStrike's IP addresses to the registry's allowlist to enable access. Option A: For CrowdStrike to assess images in a private registry, it needs network access to the registry. Adding CrowdStrike's IP addresses to the allowlist ensures that its traffic isn't blocked by access controls, enabling effective scanning while maintaining security…

Container Image Security

Question

An organization uses a private container registry protected by strict access controls. To enable CrowdStrike to perform image assessment, what must the organization do?

Options

  • AAdd CrowdStrike's IP addresses to the registry's allowlist to enable access.
  • BGrant CrowdStrike full administrative access to the container registry.
  • CAdd all container registry IP addresses to the CrowdStrike allowlist.
  • DConfigure CrowdStrike to scan images only after they are deployed.

How the community answered

(22 responses)
  • A
    73% (16)
  • B
    9% (2)
  • C
    5% (1)
  • D
    14% (3)

Explanation

Option A: For CrowdStrike to assess images in a private registry, it needs network access to the registry. Adding CrowdStrike's IP addresses to the allowlist ensures that its traffic isn't blocked by access controls, enabling effective scanning while maintaining security. Option B: CrowdStrike doesn't require administrative access to the registry. It only needs permission to scan images, granted through the allowlisting of its IP addresses. Providing administrative access introduces unnecessary security risks. Option C: Allowlisting all registry IPs in CrowdStrike is unnecessary and could create security vulnerabilities. The proper approach is to allowlist CrowdStrike's IPs in the registry, not the Option D: Scanning images post-deployment introduces security risks. CrowdStrike's design emphasizes scanning images pre-deployment to detect vulnerabilities before they are introduced into the environment.

Topics

#private container registry#image assessment#IP allowlist#registry access

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice