IOA Exclusion says - Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Source: https://falcon.crowdstrike.com/documentation/68/detection-and-prevention-policies#exclusions
I think the A option is the correct answer.
In IOA actions you can not avoid the detection, you only can monitor, detect or mitigate in any way (Kill process, Block Execution) so it is not possible to hide the detection.
In relation with the IOAs are applied to all the detections in general not only for behavioural detection, so the Machine Learning is the only choice that is related with only behavioural detections, and finally with machine learning detections it is possible avoid the detection and prevention, so I think the most logical answer is A.
About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
You are wrong. About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct anwser is B
You are right. Just for documentation confirmation.
About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
You are wrong. About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
upvoted 2 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
GreenHok
4Â months, 1Â week agoGapsiux
10Â months, 1Â week agoManuneethi
1Â year, 4Â months agoAlex_41
1Â year, 5Â months agoMSKid
1Â year, 6Â months agoxart
1Â year, 6Â months agoFerbOP
1Â year, 7Â months agokgmangle
1Â year, 8Â months agoBelrose
1Â year, 8Â months agoim2ca
1Â year, 8Â months agoKiller44010
1Â year, 8Â months agoKiller44010
1Â year, 8Â months agotestmailuc
1Â year, 8Â months agoReddington0214
1Â year, 9Â months agotestmailuc
1Â year, 8Â months agokgbac
1Â year, 9Â months agotestmailuc
1Â year, 8Â months agoShuliAbba
1Â year, 9Â months agotestmailuc
1Â year, 8Â months ago