
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 4Objective 3
4.3 Identify Potential Security Issues — Such as Malware Presence, High-Severity Common Vulnerabilities and Exposures (CVEs), Detected Leaked Secrets and Docker File Misconfigurations — from the Image Assessment Report CCCS Practice Questions (Page 6)
Part of the Pre-Runtime Protection domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
6concepts
Questions 26–27
- 26
A security engineer reviews an image assessment report for a container image that will be deployed to production. The report lists a critical CVE in the base OS packages, a high-severity CVE in a rarely used utility, a leaked AWS access key in a configuration file, and a Dockerfile instruction that runs the container as root. The team has limited time before the deployment window. Which issue should the engineer prioritize for immediate remediation?
Select an answer first - 27
An organization has a strict deployment deadline for a customer-facing application. The image assessment report shows a critical CVE in a library that is not used in the application's runtime path, a high-severity CVE in a library that is used and exposed to the internet, and a Dockerfile misconfiguration that runs the container as root. The team has time to fix only one issue before the deadline. Which issue should they fix to best reduce risk?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCCS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.