Week End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

CrowdStrike CCCS-203b CrowdStrike Certified Cloud Specialist Exam Practice Test

Demo: 17 questions
Total 58 questions

CrowdStrike Certified Cloud Specialist Questions and Answers

Question 1

You are investigating potential data exfiltration by reviewing IOAs in Falcon Cloud Security. You must check for any evidence of Defense Evasion via Impair Defenses: Disable or Modify Tools activity in your Azure environment.

Which IOA filters meet those requirements to identify any related IOAs?

Options:

A.

MITRE Tactic and Technique – Cloud provider

B.

Attack type – Cloud provider

C.

MITRE Tactic and Technique – Service

D.

Attack type – Service

Question 2

What is required to ensure you can retrieve the Falcon KAC image when deploying the Falcon Kubernetes Admission Controller (KAC) with a Helm chart?

Options:

A.

SENSOR_PLATFORM

B.

FALCON_REGION

C.

Docker

D.

API client key

Question 3

What is a primary function of the Containers and Images Compliance dashboard in CrowdStrike's Cloud Security platform?

Options:

A.

Provides a visual summary of compliance across containers and images

B.

Tracks the network performance of containers and provides detailed network usage data

C.

Allows users to automatically patch non-compliant containers and images

D.

Displays the list of all containers that are unsupported by Falcon Cloud Security with Containers

Question 4

You want to customize the GKE autopilot policy by updating the detection severity (Critical) and the detection type (CIS benchmark deviation) along with Vulnerability ExPRT.ai severities (Critical).

Which combination will trigger the prevention?

Options:

A.

Vulnerability ExPRT.ai severities (Critical), Detection severity (Critical)

B.

Vulnerability ExPRT.ai severities (Critical), Detection severity (Critical), Image misconfigurations

C.

Vulnerability ExPRT.ai severities (Critical), Detection severity (Critical), Detection type (CIS benchmark deviation)

Question 5

What is a valid reason for adding your base images into Falcon Cloud Security?

Options:

A.

Base image CVEs cannot be exploited by adversaries

B.

All base image CVEs are less risky than other CVEs

C.

Reduce duplicates when a base image is used multiple times

Question 6

As a Falcon Administrator, you must add access for an analyst to review cloud control plane IOMs.

What least privilege role should you assign them?

Options:

A.

Cloud Security Manager

B.

Kubernetes and Containers Manager

C.

Cloud Compliance Viewer

D.

CSPM Misconfiguration Viewer

Question 7

Which Falcon sensor installation should you use for a Kubernetes endpoint that is hosting container workloads when you have access to the kernel?

Options:

A.

Falcon Operator Container Image

B.

Falcon Container Sensor for Linux

C.

Falcon Sensor for Linux

D.

Falcon Sensor for Linux deployed as a DaemonSet

Question 8

What is the recommended method to block a specific CVE for 14 days when creating an Image assessment policy exclusion?

Options:

A.

Vulnerabilities published recently until 14 days

B.

Vulnerability ID & Exclude until 14 days

C.

Packages published recently until 14 days

D.

Vulnerable ID & Exclude indefinitely

Question 9

What criteria can you use to create exclusions for cloud scans?

Options:

A.

Account

B.

Region

C.

Service

D.

Tag

Question 10

What are the three Image properties that can be selected when editing a Cloud Group?

Options:

A.

Tag, Name, and Registry

B.

Name, Repository, and Registry

C.

Repository, Tag, and Name

D.

Registry, Repository, and Tag

Question 11

The internal audit team is preparing for an internal review. You have been asked to provide a list of configuration policy breaches against the NIST benchmark.

Where can you access this list?

Options:

A.

Export Cloud Posture – Cloud indicators of attack

B.

Export Cloud Posture – Indicators of misconfiguration

C.

Export Cloud Posture – Remediation status

D.

Export Cloud Posture – Cloud Posture dashboard

Question 12

How can you prevent a container process from altering the container's expected behavior?

Options:

A.

Enable container drift prevention on the Linux sensor

B.

Create a custom IOA with automated remediation

C.

Enable process modification protection on the Kubernetes Admission Controller

D.

Create an Image Assessment policy to block container drift

Question 13

What cloud-conscious attacker behavior is used to allow them to stay hidden in the environment?

Options:

A.

Storage Account Networking changed to All Networks

B.

CloudTrail logging disabled

C.

Certificate added to an application registration

D.

EC2 Default security group does not block all traffic

Question 14

Which category in the Containers dashboard can be used to identify containers that are performing activity not configured in the container image?

Options:

A.

Unidentified containers

B.

Alerts

C.

Drift indicators

D.

Container detections

Question 15

You want to deploy the Falcon sensor using 1-click sensor deployment when AWS Systems Manager is unavailable.

Which IT automation software can you use to generate an inventory of unmanaged workloads?

Options:

A.

Jet

B.

Ansible

C.

Rudder

D.

Puppet

Question 16

You no longer want to see vulnerabilities for images that are older than 90 days.

What is the most efficient way to achieve this?

Options:

A.

Use a Fusion workflow to hide the results for any images older than 90 days

B.

Delete any images in your registry that are older than 90 days

C.

Use theStop assessing images older than (number) of dayssetting

D.

Manually hide any results older than 90 days

Question 17

What is a primary benefit of using CrowdStrike's suite of cloud security products?

Options:

A.

Hunts for suspicious security control plane updates

B.

Provides a comprehensive security posture by integrating visibility and prevention

C.

Monitors file integrity and data loss prevention

D.

Provides a dedicated team to remediate cloud incidents

Demo: 17 questions
Total 58 questions