nerdexam
CrowdStrike

CCCS-203B · Question #241

A financial services company is deploying a Kubernetes cluster to manage highly ephemeral workloads that scale up and down rapidly based on demand. The security team needs a solution that provides…

The correct answer is A. Falcon Cloud Workload Protection (CWP) Sensor for Kubernetes. Option A: This is the correct choice because Falcon CWP is specifically designed for Kubernetes environments, providing visibility into containers, real-time threat detection, and runtime protection. It integrates seamlessly with Kubernetes without impacting ephemeral…

Cloud Workload Protection

Question

A financial services company is deploying a Kubernetes cluster to manage highly ephemeral workloads that scale up and down rapidly based on demand. The security team needs a solution that provides real-time runtime protection without interfering with the container orchestration process. Which CrowdStrike Falcon sensor would be the most appropriate for this use case?

Options

  • AFalcon Cloud Workload Protection (CWP) Sensor for Kubernetes
  • BFalcon LogScale for Log Analytics
  • CFalcon Sensor for Workstations
  • DFalcon Sensor for Windows Servers

How the community answered

(41 responses)
  • A
    78% (32)
  • B
    7% (3)
  • C
    12% (5)
  • D
    2% (1)

Explanation

Option A: This is the correct choice because Falcon CWP is specifically designed for Kubernetes environments, providing visibility into containers, real-time threat detection, and runtime protection. It integrates seamlessly with Kubernetes without impacting ephemeral workloads. Option B: Falcon LogScale is focused on centralized logging and event analysis. While it helps with incident investigation, it does not provide active runtime protection for Kubernetes workloads. Option C: This sensor is designed for endpoint security on user devices like laptops and desktops. It does not support Kubernetes-specific security needs such as container introspection and runtime threat detection. Option D: While the Windows server sensor is useful for traditional on-prem and cloud-hosted VMs, it is not optimized for containerized workloads in Kubernetes. It lacks deep container visibility and runtime protection features specific to Kubernetes.

Topics

#Falcon sensor deployment#Kubernetes security#container workloads#runtime protection

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice