CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 29: CA1-005: CompTIA SecurityX

A security engineer wants to reduce the attack surface of a public-facing containerized application. Which of the following will best reduce the application's privilege escalation attack surface?

Nội dung câu hỏi

A security engineer wants to reduce the attack surface of a public-facing containerized application. Which of the following will best reduce the application's privilege escalation attack surface?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Implementing the following commands in the Dockerfile:RUN echo user:x:1000:1000:user:/home/user:/dev/null > /etc/passwd — đáp án hiện tại
  2. B. Installing an EDR on the container's host, with reporting configured to log to a centralized SIEM, and implementing the following alerting rule:IF PROCESS_USER==root ALERT_TYPE==critical
  3. C. Designing a multicontainer solution, with one set of containers that runs the main application, and another set of containers that performs automatic remediation by replacing compromised containers or disabling compromised accounts
  4. D. Running the container in an isolated network and placing a load balancer in a public-facing network. Adding the following ACL to the load balancer:PERMIT HTTPS from 0.0.0.0.0/0 port 443

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề