Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CloudBees Exam CCJE Topic 4 Question 61 Discussion

Actual exam question for CloudBees's Certified CloudBees Jenkins Engineer (CCJE) exam
Question #: 61
Topic #: 4
[All Certified CloudBees Jenkins Engineer (CCJE) Questions]

You are the administrator of a base Jenkins master with the recommended set of plugins installed. You want to protect the Jenkins master against malicious (or bad) usages of Groovy methods. You also want your users to be able to share their Pipeline code via Globa Pipeline Libraries housed on a git repository under your company's Github Organization. Which of the following statements is TRUE?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

Erin
2 days ago
I think the answer is A. Setting up Global Pipeline Libraries at the Github Organization level with untrusted code seems like the safest option.
upvoted 0 times
...
Pearly
24 days ago
Yeah, that makes sense. But B) says we shouldn't configure any Global Pipeline Libraries at the folder level, and that the libraries would be running as 'trusted' code, allowing all developers to execute privileged methods. That sounds like a big security risk.
upvoted 0 times
...
Ivette
26 days ago
Alright, let's dive into the options. A) seems to suggest configuring Global Pipeline Libraries at the Github Organization level, with the libraries running as 'untrusted' code. That would allow developers to run code in the Groovy sandbox, which sounds like a good security measure.
upvoted 0 times
...
Raylene
27 days ago
Haha, 'trusted' and 'untrusted' code, it's like we're dealing with superheroes and supervillains here! But in all seriousness, this is an important distinction.
upvoted 0 times
...
Darnell
28 days ago
Exactly. I think the key here is whether the libraries are running as 'trusted' or 'untrusted' code. That will determine what kind of access they have to the Jenkins master.
upvoted 0 times
...
Vivan
1 months ago
I agree. And the ability to share Pipeline code through Global Pipeline Libraries is a really useful feature, but we need to make sure it's set up securely.
upvoted 0 times
...
Carmen
1 months ago
Hmm, this question seems to be testing our understanding of Jenkins' security configurations. Protecting the Jenkins master from malicious Groovy methods is definitely a critical concern.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77