Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCFA All Questions

View all questions & answers for the CCFA exam

Exam CCFA topic 1 question 167 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 167
Topic #: 1
[All CCFA Questions]

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to, "C:\Users\Bob\DevCode\felix.dll". In the detection, you see that it's triggering only on a specific Falcon IOA. What would be the best course of action for this situation?

  • A. Create a sensor visibility exclusion for "C:\Users\Bob\DevCode\felix.dll"
  • B. Create an IOA exclusion for "C:\Users\Bob\DevCode\felix.dll"
  • C. Create a Custom IOC and set it to "Allow" for "C:\Users\Bob\DevCode\felix.dll"
  • D. Manually turn off the built-in IOA through prevention policies
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
kitkat007
2 months ago
Selected Answer: B
B. Create an IOA exclusion for "C:\Users\Bob\DevCode\felix.dll" In this situation, the alert is triggered by a specific Falcon Indicator of Attack (IOA), so the best course of action would be to create an IOA exclusion for the specific file path to prevent Falcon from flagging it during testing. This allows the development process to continue without compromising overall security, as the exclusion is targeted and specific to the identified IOA.
upvoted 1 times
...
Muffen
7 months, 1 week ago
Selected Answer: B
Answer is B because the detection was for an IOA. If you allow the hash of the DLL via a Custom IOC it will only affect Machine Learning based detections and not IOAs, which means it cannot be C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...