Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCFA All Questions

View all questions & answers for the CCFA exam

Exam CCFA topic 1 question 3 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 3
Topic #: 1
[All CCFA Questions]

What is the purpose of a containment policy?

  • A. To define which Falcon analysts can contain endpoints
  • B. To define the duration of Network Containment
  • C. To define the trigger under which a machine is put in Network Containment (e.g. a critical detection)
  • D. To define allowed IP addresses over which your hosts will communicate when contained
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
vsnt89
2 months, 3 weeks ago
Selected Answer: D
The correct answer is D. Here is the explanation taken from the official CrowdStrike documentation: "On the Containment Policy page, you can allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained."
upvoted 1 times
...
AntiVirusAshok
3 months, 4 weeks ago
Selected Answer: C
Option C is correct: While defining allowed IP addresses over which your hosts will communicate when contained is important, it is typically part of a broader network configuration or security policy rather than the primary purpose of a containment policy. A containment policy specifically focuses on the conditions or triggers that necessitate placing a machine into network containment, such as detecting a critical threat. This helps ensure that immediate action is taken to isolate the affected machine and prevent the spread of potential threats.
upvoted 1 times
...
AntiVirusAshok
3 months, 4 weeks ago
Option C is correct: While defining allowed IP addresses over which your hosts will communicate when contained is important, it is typically part of a broader network configuration or security policy rather than the primary purpose of a containment policy. A containment policy specifically focuses on the conditions or triggers that necessitate placing a machine into network containment, such as detecting a critical threat. This helps ensure that immediate action is taken to isolate the affected machine and prevent the spread of potential threats.
upvoted 1 times
...
CyberMacadamia
8 months ago
Selected Answer: D
D is correct, can be seen in UI under Host Setup and Management > Containment Policy > Add allowlist entry
upvoted 3 times
AntiVirusAshok
3 months, 4 weeks ago
While defining allowed IP addresses over which your hosts will communicate when contained is important, it is typically part of a broader network configuration or security policy rather than the primary purpose of a containment policy. A containment policy specifically focuses on the conditions or triggers that necessitate placing a machine into network containment, such as detecting a critical threat. This helps ensure that immediate action is taken to isolate the affected machine and prevent the spread of potential threats.
upvoted 1 times
...
...
diegofretesc
1 year, 2 months ago
El D es el correcto
upvoted 2 times
...
sbag0024
1 year, 5 months ago
Selected Answer: D
D is correct
upvoted 3 times
...
MSKid
1 year, 6 months ago
Selected Answer: D
Yup, its D
upvoted 3 times
...
FerbOP
1 year, 7 months ago
Selected Answer: D
D, Network traffic allowlist
upvoted 3 times
...
chaos_mob
1 year, 7 months ago
Selected Answer: D
Checked the portal and it is D
upvoted 3 times
...
Belrose
1 year, 8 months ago
Selected Answer: D
D is correct, In the Containment Policy page have the title "Network traffic allowlist" and it only allows to add IPs or CIDR networks to exclude in the moment of the isolation of any host, because it is a global policy, not allowing make distinctions between machines.
upvoted 3 times
...
ShuliAbba
1 year, 10 months ago
Verified with Falcon's documentation - D is correct.
upvoted 3 times
...
plantvast
1 year, 10 months ago
Selected Answer: D
Tested on Falcon. Containment policy is only used to allow communication to specific IPs or IP ranges when a host is contained.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...