CCCS-203B · Question #51
What is the recommended course of action after identifying unassessed images in production using CrowdStrike Falcon?
The correct answer is B. Conduct a vulnerability assessment on the identified images and update policies as needed. Option A: Runtime protection policies can prevent the execution of specific images but cannot remediate vulnerabilities automatically. Remediation requires manual steps or integration with Option B: After identifying unassessed images, performing a vulnerability assessment…
Question
What is the recommended course of action after identifying unassessed images in production using CrowdStrike Falcon?
Options
- AUse the Falcon runtime protection policy to automatically remediate vulnerabilities.
- BConduct a vulnerability assessment on the identified images and update policies as needed.
- CConfigure a backup server to replace containers using unassessed images.
- DImmediately stop all containers using unassessed images to avoid security risks.
How the community answered
(25 responses)- A4% (1)
- B72% (18)
- C16% (4)
- D8% (2)
Explanation
Option A: Runtime protection policies can prevent the execution of specific images but cannot remediate vulnerabilities automatically. Remediation requires manual steps or integration with Option B: After identifying unassessed images, performing a vulnerability assessment ensures any potential risks are addressed. Updating policies to enforce assessments in the future prevents similar gaps. Option C: Replacing containers without assessing vulnerabilities might result in similar risks. The priority should be to scan the images and mitigate vulnerabilities proactively. Option D: Stopping all containers using unassessed images might disrupt business operations. A more measured approach is to assess vulnerabilities first and take appropriate actions based on
Topics
Community Discussion
No community discussion yet for this question.