nerdexam
CrowdStrike

CCCS-203B · Question #78

Which method can be used to identify running processes in a cloud environment without deploying a Falcon sensor?

The correct answer is C. Cloud-native tools like AWS CloudWatch, Azure Monitor, or Google Cloud Operations Suite. Option A: While Falcon Discover provides comprehensive visibility into cloud workloads, it requires deployment on monitored environments. The question specifies identifying running processes without deploying a Falcon sensor, so this option is invalid. Option B: Manually SSHing i

Cloud Workload Protection

Question

Which method can be used to identify running processes in a cloud environment without deploying a Falcon sensor?

Options

  • ADeploy Falcon Discover for Cloud Environments
  • BSSH into each virtual machine to manually inspect running processes
  • CCloud-native tools like AWS CloudWatch, Azure Monitor, or Google Cloud Operations Suite
  • DRely on the built-in antivirus solutions of the cloud provider

How the community answered

(16 responses)
  • B
    6% (1)
  • C
    88% (14)
  • D
    6% (1)

Explanation

Option A: While Falcon Discover provides comprehensive visibility into cloud workloads, it requires deployment on monitored environments. The question specifies identifying running processes without deploying a Falcon sensor, so this option is invalid. Option B: Manually SSHing into VMs to inspect processes is inefficient and does not scale in modern cloud environments. This method increases administrative overhead and risks configuration drift. Additionally, SSH access may not be available due to strict security policies. Option C: Cloud-native monitoring tools like AWS CloudWatch, Azure Monitor, and Google Cloud Operations Suite allow visibility into running processes, system metrics, and logs without requiring third-party agents. These services can provide runtime data and integrate with CrowdStrike for deeper insights. They are essential for environments where agent installation is limited by operational constraints. Option D: Built-in antivirus solutions, such as Microsoft Defender for Endpoint or AWS GuardDuty, focus on threat detection rather than providing detailed runtime process visibility. These tools lack the specificity required to identify and monitor all running processes.

Topics

#agentless monitoring#cloud-native tools#CloudWatch#Azure Monitor

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice