ExamGecko
Question list
Search
Search

List of questions

Search

Question 76 - PCCSE discussion

Report
Export

An administrator sees that a runtime audit has been generated for a Container. The audit message is ''DNS resolution of suspicious name wikipedia.com. type A''.

Why would this message appear as an audit?

A.
The DNS was not learned as part of the Container model or added to the DNS allow list.
Answers
A.
The DNS was not learned as part of the Container model or added to the DNS allow list.
B.
This is a DNS known to be a source of malware.
Answers
B.
This is a DNS known to be a source of malware.
C.
The process calling out to this domain was not part of the Container model.
Answers
C.
The process calling out to this domain was not part of the Container model.
D.
The Layer7 firewall detected this as anomalous behavior.
Answers
D.
The Layer7 firewall detected this as anomalous behavior.
Suggested answer: A

Explanation:

The runtime audit message indicating 'DNS resolution of suspicious name wikipedia.com. type A' would appear as an audit because the DNS was not learned as part of the Container model or added to the DNS allow list (option A). In cloud security platforms like Prisma Cloud, runtime protection policies monitor the behavior of running containers and compare it against a learned model of expected behavior. If a container attempts to resolve a DNS name that was not observed during the learning phase or specifically allowed, it triggers an audit event to alert security teams of potentially malicious activity.

asked 23/09/2024
sailakshmi KM
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first