Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Cloud Specialist (CCCS)

Domain 4Objective 3

4.3 Identify Potential Security Issues — Such as Malware Presence, High-Severity Common Vulnerabilities and Exposures (CVEs), Detected Leaked Secrets and Docker File Misconfigurations — from the Image Assessment Report CCCS Practice Questions (Page 4)

Part of the Pre-Runtime Protection domain, which makes up ~16% of our current practice bank.

27questions here
6free pages
6concepts

Questions 16–20

  1. 16application · medium

    A DevOps engineer runs an image assessment on a container image before promoting it to a production registry. The report shows a malware detection in a layer that installs a third-party library. The engineer needs to decide the next step. What should the engineer do first?

    Select an answer first
  2. 17application · medium

    An image assessment report for a web application container lists several CVEs. The application is internet-facing and handles sensitive customer data. Which CVE should the team address first?

    Select an answer first
  3. 18foundation · easy

    An image assessment report flags a hardcoded API key in the image. What type of finding is this?

    Select an answer first
  4. 19application · medium

    A security analyst is reviewing an image assessment report and notices that the report includes a section called 'Findings' that lists malware detections, CVEs, and leaked secrets. The analyst wants to understand the severity of each finding. Where should the analyst look?

    Select an answer first
  5. 20application · medium

    A Dockerfile for a web application includes the instruction `RUN apt-get install -y curl`. The image assessment report flags this as a potential security issue. What is the most likely reason?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.