nerdexam
CrowdStrike

CCCS-203B · Question #82

A security administrator is configuring pre-runtime protection in CrowdStrike Falcon to ensure that only trusted container images from specific registries are scanned and allowed for deployment. What

The correct answer is C. Specify the registry URL, enable authentication if required, and configure scanning policies for. Option A: Default Falcon registry settings may not cover all organizational needs. Custom configurations should be made to ensure alignment with security policies. Option B: Allowing all registries without authentication increases security risks, as unauthorized or malicious imag

Container and Kubernetes Security

Question

A security administrator is configuring pre-runtime protection in CrowdStrike Falcon to ensure that only trusted container images from specific registries are scanned and allowed for deployment. What is the best approach for adding registry connection details?

Options

  • ASet up registry connections using only the default Falcon registry settings without modifications.
  • BAdd all public and private container registries without authentication to ensure maximum
  • CSpecify the registry URL, enable authentication if required, and configure scanning policies for
  • DDisable scanning for images from private repositories since they are already trusted and internally

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    71% (15)
  • D
    19% (4)

Explanation

Option A: Default Falcon registry settings may not cover all organizational needs. Custom configurations should be made to ensure alignment with security policies. Option B: Allowing all registries without authentication increases security risks, as unauthorized or malicious images can be pulled and deployed. Option C: To ensure pre-runtime protection, administrators should define registry connection details, specify the registry URL, enable authentication (if needed), and set image scanning policies for security compliance. Option D: Private repositories are not automatically secure. Vulnerabilities can still exist in private images, making it critical to enable scanning even for internal sources.

Topics

#pre-runtime protection#registry integration#image scanning#authentication configuration

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice