nerdexam
CrowdStrike

CCCS-203B · Question #40

A security team has identified an outdated Kubernetes Admission Controller policy in Falcon Cloud Security that enforces image signing requirements for container workloads. They need to update the pol

The correct answer is A. Modify the existing policy directly in the Falcon Cloud Security Console.. Option A: The Falcon Cloud Security Console provides tools to edit existing policies, ensuring that changes are implemented efficiently without creating redundant configurations or policies. Option B: Falcon Cloud Security does not require exporting and re-importing YAML files fo

Container Security

Question

A security team has identified an outdated Kubernetes Admission Controller policy in Falcon Cloud Security that enforces image signing requirements for container workloads. They need to update the policy to align with new organizational guidelines. What is the most appropriate way to edit this policy?

Options

  • AModify the existing policy directly in the Falcon Cloud Security Console.
  • BExport the existing policy as a YAML file, edit it locally, and re-import it to Falcon Cloud Security.
  • CDisable the existing policy in Falcon Cloud Security and replace it with a new Kubernetes
  • DDelete the current policy and create a new one from scratch.

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Option A: The Falcon Cloud Security Console provides tools to edit existing policies, ensuring that changes are implemented efficiently without creating redundant configurations or policies. Option B: Falcon Cloud Security does not require exporting and re-importing YAML files for policy updates. Changes are made directly in the console. Option C: Falcon Cloud Security Admission Controller policies are managed in the Falcon Console, not through Kubernetes ConfigMaps. Disabling and replacing the policy is not the correct approach. Option D: Deleting and recreating the policy is unnecessary and could introduce downtime or configuration gaps. Editing the policy is more efficient and preserves continuity.

Topics

#Kubernetes Admission Controller#policy management#image signing#container security

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice