CCCS-203B · Question #229
An organization uses a private container registry protected by strict access controls. To enable CrowdStrike to perform image assessment, what must the organization do?
The correct answer is A. Add CrowdStrike's IP addresses to the registry's allowlist to enable access. Option A: For CrowdStrike to assess images in a private registry, it needs network access to the registry. Adding CrowdStrike's IP addresses to the allowlist ensures that its traffic isn't blocked by access controls, enabling effective scanning while maintaining security…
Question
An organization uses a private container registry protected by strict access controls. To enable CrowdStrike to perform image assessment, what must the organization do?
Options
- AAdd CrowdStrike's IP addresses to the registry's allowlist to enable access.
- BGrant CrowdStrike full administrative access to the container registry.
- CAdd all container registry IP addresses to the CrowdStrike allowlist.
- DConfigure CrowdStrike to scan images only after they are deployed.
How the community answered
(22 responses)- A73% (16)
- B9% (2)
- C5% (1)
- D14% (3)
Explanation
Option A: For CrowdStrike to assess images in a private registry, it needs network access to the registry. Adding CrowdStrike's IP addresses to the allowlist ensures that its traffic isn't blocked by access controls, enabling effective scanning while maintaining security. Option B: CrowdStrike doesn't require administrative access to the registry. It only needs permission to scan images, granted through the allowlisting of its IP addresses. Providing administrative access introduces unnecessary security risks. Option C: Allowlisting all registry IPs in CrowdStrike is unnecessary and could create security vulnerabilities. The proper approach is to allowlist CrowdStrike's IPs in the registry, not the Option D: Scanning images post-deployment introduces security risks. CrowdStrike's design emphasizes scanning images pre-deployment to detect vulnerabilities before they are introduced into the environment.
Topics
Community Discussion
No community discussion yet for this question.