
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 4Objective 3
4.3 Identify Potential Security Issues — Such as Malware Presence, High-Severity Common Vulnerabilities and Exposures (CVEs), Detected Leaked Secrets and Docker File Misconfigurations — from the Image Assessment Report CCCS Practice Questions (Page 4)
Part of the Pre-Runtime Protection domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
6concepts
Questions 16–20
- 16
A DevOps engineer runs an image assessment on a container image before promoting it to a production registry. The report shows a malware detection in a layer that installs a third-party library. The engineer needs to decide the next step. What should the engineer do first?
Select an answer first - 17
An image assessment report for a web application container lists several CVEs. The application is internet-facing and handles sensitive customer data. Which CVE should the team address first?
Select an answer first - 18
An image assessment report flags a hardcoded API key in the image. What type of finding is this?
Select an answer first - 19
A security analyst is reviewing an image assessment report and notices that the report includes a section called 'Findings' that lists malware detections, CVEs, and leaked secrets. The analyst wants to understand the severity of each finding. Where should the analyst look?
Select an answer first - 20
A Dockerfile for a web application includes the instruction `RUN apt-get install -y curl`. The image assessment report flags this as a potential security issue. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.