nerdexam
CrowdStrike

CCCS-203B · Question #33

A company using CrowdStrike Falcon Cloud Security wants to enforce strict vulnerability scanning for container images but needs to exclude certain trusted base images used in internal applications…

The correct answer is D. Define allowlists for specific trusted base images to exempt them from enforcement but still scan. Option A: Disabling scanning entirely would remove critical security controls and increase risk of deploying vulnerable images. Option B: A blanket block on all vulnerable images could disrupt internal operations, especially if some vulnerabilities do not impact security…

Container Security

Question

A company using CrowdStrike Falcon Cloud Security wants to enforce strict vulnerability scanning for container images but needs to exclude certain trusted base images used in internal applications to reduce false positives. What is the best way to configure policy exclusions while maintaining strong security?

Options

  • ACompletely disable vulnerability scanning for all images to avoid unnecessary alerts.
  • BBlock all images that contain vulnerabilities, even if they come from an approved internal
  • CExclude all container images from scanning that originate from private repositories.
  • DDefine allowlists for specific trusted base images to exempt them from enforcement but still scan

How the community answered

(60 responses)
  • A
    22% (13)
  • B
    5% (3)
  • C
    7% (4)
  • D
    67% (40)

Explanation

Option A: Disabling scanning entirely would remove critical security controls and increase risk of deploying vulnerable images. Option B: A blanket block on all vulnerable images could disrupt internal operations, especially if some vulnerabilities do not impact security posture. Option C: Excluding all images from private repositories is risky, as internal repositories can still contain vulnerabilities and require security checks. Option D: Allowlisting specific, trusted base images ensures that known good images are not unnecessarily blocked while still being monitored for visibility. This approach balances security and operational efficiency.

Topics

#vulnerability scanning#policy exclusions#allowlists#container image security

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice