Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CrowdStrike Certified Cloud Specialist CCCS-203b Exam Questions

Page: 1 / 6 Total 58 questions

Want more questions? Get Premium Access.

Question 1

You receive an alert that one of your container images contains AWS credentials stored in cleartext.

What detection type should you search for to investigate?

Correct Answer: D. Secret When CrowdStrike Falcon detects cloud credentials---such as AWS access keys---stored in cleartext within a container image, the finding is classified as a Secret detection. Secrets include sensitive data such as API keys, access tokens, passwords, and cryptographic material embedded in container images, configuration files, or source code. Falcon Cloud Security performs deep inspection of container images during image assessment to identify hard-coded secrets before those images are deployed into runtime environments. Storing AWS credentials in cleartext represents a critical security risk because attackers who gain access to the image can easily extract and misuse those credentials to access cloud resources. While misconfigurations focus on insecure cloud settings and suspicious files relate to potentially malicious artifacts, secret detections are specifically intended to highlight exposed sensitive information. The Exposed credential option may sound similar, but within CrowdStrike's detection taxonomy for container and image security, these findings are categorized under Secret detections. Investigating Secret detections allows security teams to quickly identify where credentials are embedded, rotate compromised keys, and remediate the issue by using secure alternatives such as cloud-native secrets managers or environment-based injection mechanisms. Therefore, the correct detection type to search for is Secret.

Question 2

CrowdStrike pulls data via API from AWS, Azure, and GCP without an agent to identify misconfigurations.

What is the default scan interval set to for each cloud provider?

Correct Answer: C. Every 4 hours

Question 3

What is one purpose of the CrowdStrike Kubernetes Admission Controller?

Correct Answer: C. Monitors and enforces security policies in any containerized environment The CrowdStrike Kubernetes Admission Controller is a pre-runtime security control designed to enforce security policies before workloads are allowed to run in a Kubernetes environment. Its primary purpose is to monitor and enforce security policies in any containerized environment by intercepting Kubernetes API requests at admission time. When a deployment, pod, or container is submitted to the Kubernetes API server, the Admission Controller evaluates the request against Falcon Cloud Security policies. These policies can include rules related to image risk posture, vulnerabilities, malware presence, secrets, or compliance violations. If an image violates defined policies, the Admission Controller can block the deployment, preventing insecure or non-compliant workloads from entering the cluster. This capability is critical for implementing a shift-left security model, ensuring that threats are stopped before runtime, rather than detected after execution. While Falcon also provides runtime protection and visibility across managed Kubernetes platforms such as EKS and AKS, those capabilities are not the primary function of the Admission Controller itself. The Admission Controller does not forward Kubernetes logs to SIEM platforms; instead, it acts as an enforcement gate. Therefore, the correct answer is Monitors and enforces security policies in any containerized environment.

Question 4

There is a valid sensor update policy for all Linux hosts that is set to n-2. Some of the hosts have not updated their sensor version.

What is the reason for this situation?

Correct Answer: A. DaemonSet was used for deployment

Question 5

You want to block privileged containers from being executed in your Kubernetes cluster.

What sensor type should you deploy?

Correct Answer: D. Kubernetes Admission Controller To block privileged containers before they are executed, CrowdStrike recommends deploying the Kubernetes Admission Controller. This component operates at admission time, intercepting Kubernetes API requests and enforcing security policies before workloads are allowed to run. Privileged containers represent a significant security risk because they can bypass isolation boundaries and access host resources. The Kubernetes Admission Controller can enforce policies that explicitly deny deployments using privileged flags, hostPath mounts, or other high-risk configurations. Other options do not provide enforcement. Runtime sensors and agents can detect or alert on risky behavior after execution, but they cannot prevent the workload from starting. Image assessment evaluates image content but does not enforce Kubernetes runtime constraints. Therefore, to proactively block privileged containers, the correct and CrowdStrike-recommended solution is the Kubernetes Admission Controller.

Question 6

Which action is required when creating a new image registry connection that accesses a privately hosted registry?

Correct Answer: D. Verify the token and secret When configuring a new image registry connection for a privately hosted container registry in CrowdStrike Falcon Cloud Security, the required and most critical action is to verify the token and secret used for authentication. Private registries require explicit credentials so Falcon can securely access and assess container images for vulnerabilities, malware, and misconfigurations. CrowdStrike supports multiple private registry types (such as private Docker registries or cloud-native registries with restricted access). In all cases, Falcon relies on valid authentication credentials---typically a token, username/password, or service account secret---to pull image metadata and layers. If these credentials are incorrect, expired, or misconfigured, image assessment will fail even if the registry connection appears configured. Other options may be relevant in specific environments but are not universally required at creation time. Registry URLs are validated during setup, and allowlisting IP addresses may be necessary only if strict network controls are in place. Secret expiration checks are a maintenance concern, not a mandatory creation step. Therefore, the required action when creating a private registry connection is to verify the token and secret.

Question 7

Your organization is deploying containerized applications in a cloud environment. You must ensure that container images are free of vulnerabilities before being deployed into production. The solution must integrate seamlessly with your CI/CD pipeline to automate image scanning during the build process.

Which image assessment method is in accordance with CrowdStrike best practices?

Correct Answer: B. Integrate pushing images for assessment into your CI/CD pipeline to detect vulnerabilities during the build process

Question 8

You are setting up a Falcon Fusion SOAR workflow to notify your team when any new executable is downloaded to a container and run. You are using a Kubernetes and containers trigger.

Which trigger subcategory and type should you select for this purpose?

Correct Answer: C. Container detection > Container runtime detection

Question 9

What is a primary benefit of using CrowdStrike's suite of cloud security products?

Correct Answer: B. Provides a comprehensive security posture by integrating visibility and prevention

Question 10

Which are valid attributes when creating an image group?

Correct Answer: B. Repository and Image tags