nerdexam
CrowdStrike

CCCS-203B · Question #259

What action should a security engineer prioritize to mitigate the risks of unassessed container images running in production using CrowdStrike Falcon?

The correct answer is B. Enable Image Drift Detection with Runtime Visibility. Option A: Threat intelligence feeds enhance detection of malicious activity, but they are not specifically tailored for identifying unassessed container images in runtime environments. Option B: CrowdStrike Falcon includes drift detection, which identifies when a running…

Container Image Security

Question

What action should a security engineer prioritize to mitigate the risks of unassessed container images running in production using CrowdStrike Falcon?

Options

  • AUse Threat Intelligence Feeds to Block Threats at the Network Level
  • BEnable Image Drift Detection with Runtime Visibility
  • CRun a Manual Audit of Deployed Containers
  • DImplement Network Segmentation for All Workload

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    74% (28)
  • C
    16% (6)
  • D
    3% (1)

Explanation

Option A: Threat intelligence feeds enhance detection of malicious activity, but they are not specifically tailored for identifying unassessed container images in runtime environments. Option B: CrowdStrike Falcon includes drift detection, which identifies when a running container image deviates from its baseline configuration or assessment status. This real-time feature allows security teams to pinpoint unassessed images and mitigate risks proactively. Runtime visibility ensures any image running without prior assessment is flagged. Option C: Manual audits are time-consuming and prone to human error. They lack the scalability and real-time capabilities provided by tools like CrowdStrike Falcon for detecting unassessed images in runtime. Option D: While network segmentation can limit the impact of compromised containers, it does not address identifying or mitigating risks from unassessed images directly.

Topics

#image drift detection#runtime visibility#unassessed container images#production security

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice