
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 5Objective 5
5.5 Identify Indicators of Attack (IOAs), Rogue Containers and Drift CCCS Practice Questions (Page 3)
Part of the Runtime Protection domain, which makes up ~18% of our current practice bank.
24questions here
5free pages
7concepts
Questions 11–15
- 11
A DevOps team uses a containerized application that periodically fetches configuration from an internal service. The runtime security tool flags a container that is making repeated outbound connections to a public IP on port 4444, and the process tree shows a child process named 'nc' spawned from the main application. Which IOA is most clearly indicated?
Select an answer first - 12
A security team wants to implement drift detection for their containerized applications. They have a policy that requires detecting any changes to critical files, such as binaries and configuration files, but they want to minimize false positives from ephemeral files like logs. Which approach best meets this requirement?
Select an answer first - 13
A security engineer notices a container running in a production Kubernetes cluster that is not listed in the deployment manifests. The container's image is from a public registry, and it has a high CPU usage pattern. The engineer needs to determine if this is a rogue container. Which combination of signals best confirms this?
Select an answer first - 14
Which of the following behaviors is a typical Indicator of Attack (IOA) related to privilege escalation?
Select an answer first - 15
Which of the following scenarios best describes a rogue container?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.