CCCS-203B · Question #259
What action should a security engineer prioritize to mitigate the risks of unassessed container images running in production using CrowdStrike Falcon?
The correct answer is B. Enable Image Drift Detection with Runtime Visibility. Option A: Threat intelligence feeds enhance detection of malicious activity, but they are not specifically tailored for identifying unassessed container images in runtime environments. Option B: CrowdStrike Falcon includes drift detection, which identifies when a running…
Question
What action should a security engineer prioritize to mitigate the risks of unassessed container images running in production using CrowdStrike Falcon?
Options
- AUse Threat Intelligence Feeds to Block Threats at the Network Level
- BEnable Image Drift Detection with Runtime Visibility
- CRun a Manual Audit of Deployed Containers
- DImplement Network Segmentation for All Workload
How the community answered
(38 responses)- A8% (3)
- B74% (28)
- C16% (6)
- D3% (1)
Explanation
Option A: Threat intelligence feeds enhance detection of malicious activity, but they are not specifically tailored for identifying unassessed container images in runtime environments. Option B: CrowdStrike Falcon includes drift detection, which identifies when a running container image deviates from its baseline configuration or assessment status. This real-time feature allows security teams to pinpoint unassessed images and mitigate risks proactively. Runtime visibility ensures any image running without prior assessment is flagged. Option C: Manual audits are time-consuming and prone to human error. They lack the scalability and real-time capabilities provided by tools like CrowdStrike Falcon for detecting unassessed images in runtime. Option D: While network segmentation can limit the impact of compromised containers, it does not address identifying or mitigating risks from unassessed images directly.
Topics
Community Discussion
No community discussion yet for this question.