nerdexam
CrowdStrike

CCCS-203B · Question #51

What is the recommended course of action after identifying unassessed images in production using CrowdStrike Falcon?

The correct answer is B. Conduct a vulnerability assessment on the identified images and update policies as needed. Option A: Runtime protection policies can prevent the execution of specific images but cannot remediate vulnerabilities automatically. Remediation requires manual steps or integration with Option B: After identifying unassessed images, performing a vulnerability assessment…

Image Assessment and Registry Security

Question

What is the recommended course of action after identifying unassessed images in production using CrowdStrike Falcon?

Options

  • AUse the Falcon runtime protection policy to automatically remediate vulnerabilities.
  • BConduct a vulnerability assessment on the identified images and update policies as needed.
  • CConfigure a backup server to replace containers using unassessed images.
  • DImmediately stop all containers using unassessed images to avoid security risks.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    72% (18)
  • C
    16% (4)
  • D
    8% (2)

Explanation

Option A: Runtime protection policies can prevent the execution of specific images but cannot remediate vulnerabilities automatically. Remediation requires manual steps or integration with Option B: After identifying unassessed images, performing a vulnerability assessment ensures any potential risks are addressed. Updating policies to enforce assessments in the future prevents similar gaps. Option C: Replacing containers without assessing vulnerabilities might result in similar risks. The priority should be to scan the images and mitigate vulnerabilities proactively. Option D: Stopping all containers using unassessed images might disrupt business operations. A more measured approach is to assess vulnerabilities first and take appropriate actions based on

Topics

#unassessed images#vulnerability assessment#image policy#production security

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice