ExamGecko
Question list
Search
Search

List of questions

Search

Question 95 - PCCSE discussion

Report
Export

An administrator sees that a runtime audit has been generated for a container.

The audit message is:

''/bin/ls launched and is explicitly blocked in the runtime rule. Full command: ls -latr''

Which protection in the runtime rule would cause this audit?

A.
Networking
Answers
A.
Networking
B.
File systems
Answers
B.
File systems
C.
Processes
Answers
C.
Processes
D.
Container
Answers
D.
Container
Suggested answer: C

Explanation:

The protection in the runtime rule that would cause the audit message indicating '/bin/ls launched and is explicitly blocked in the runtime rule' is related to 'Processes'. In container security, a runtime rule set to monitor and restrict processes can block specific executables or commands from running within a container. If the rule is triggered, it indicates that a process that is explicitly denied by the policy attempted to execute, which in this case is the 'ls' command.

https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/runtime_defense/runtime_audits

asked 23/09/2024
Friedrich Spies
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first