CCCS-203B · Question #6
A security team is tasked with ensuring that all installed packages in their cloud workloads are regularly analyzed for vulnerabilities. They want to integrate CrowdStrike Falcon's pre-runtime…
The correct answer is B. Utilize Falcon Spotlight to scan for vulnerabilities and integrate with patch management solutions. Option A: Even trusted vendors can distribute software with vulnerabilities. Without vulnerability scanning, critical security issues in dependencies could go undetected. Option B: Falcon Spotlight provides automated vulnerability scanning for installed packages, identifying…
Question
A security team is tasked with ensuring that all installed packages in their cloud workloads are regularly analyzed for vulnerabilities. They want to integrate CrowdStrike Falcon's pre-runtime protection to enhance security visibility. What is the most effective approach for detecting and mitigating vulnerabilities before execution?
Options
- AOnly allow software installations from trusted vendors without performing vulnerability scanning
- BUtilize Falcon Spotlight to scan for vulnerabilities and integrate with patch management solutions
- CRely on traditional antivirus (AV) software to detect vulnerabilities in installed packages
- DImplement only network-based intrusion detection systems (IDS) to monitor for suspicious activity
How the community answered
(32 responses)- A3% (1)
- B75% (24)
- C16% (5)
- D6% (2)
Explanation
Option A: Even trusted vendors can distribute software with vulnerabilities. Without vulnerability scanning, critical security issues in dependencies could go undetected. Option B: Falcon Spotlight provides automated vulnerability scanning for installed packages, identifying risks before execution. Integrating with a patch management solution ensures quick remediation of detected vulnerabilities. Option C: Traditional AV software primarily detects known malware signatures but does not provide proactive vulnerability scanning for installed software. Dedicated vulnerability management tools are necessary. Option D: IDS solutions detect suspicious network activity but do not proactively identify vulnerabilities in installed packages. Pre-runtime vulnerability scanning is essential for mitigating risks before execution.
Topics
Community Discussion
No community discussion yet for this question.