Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCFA All Questions

View all questions & answers for the CCFA exam

Exam CCFA topic 1 question 34 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 34
Topic #: 1
[All CCFA Questions]

Which option allows you to exclude behavioral detections from the detections page?

  • A. Machine Learning Exclusion
  • B. IOA Exclusion
  • C. IOC Exclusion
  • D. Sensor Visibility Exclusion
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
GreenHok
4 months, 1 week ago
Selected Answer: B
B is correct
upvoted 1 times
...
Gapsiux
10 months, 1 week ago
B is correct. From CS KB: Stop all behavioural detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
upvoted 2 times
...
Manuneethi
1 year, 4 months ago
B is correct. The option under Exclusion-2nd option IOA Exclusions
upvoted 1 times
...
Alex_41
1 year, 5 months ago
IOA Exclusion says - Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection. Source: https://falcon.crowdstrike.com/documentation/68/detection-and-prevention-policies#exclusions
upvoted 2 times
...
MSKid
1 year, 6 months ago
Selected Answer: B
IOA is correct
upvoted 1 times
...
xart
1 year, 6 months ago
Selected Answer: B
IOA Exclusion is correct
upvoted 1 times
...
FerbOP
1 year, 7 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
kgmangle
1 year, 8 months ago
Selected Answer: B
Correct Answer is B
upvoted 1 times
...
Belrose
1 year, 8 months ago
Selected Answer: A
I think the A option is the correct answer. In IOA actions you can not avoid the detection, you only can monitor, detect or mitigate in any way (Kill process, Block Execution) so it is not possible to hide the detection. In relation with the IOAs are applied to all the detections in general not only for behavioural detection, so the Machine Learning is the only choice that is related with only behavioural detections, and finally with machine learning detections it is possible avoid the detection and prevention, so I think the most logical answer is A.
upvoted 2 times
...
im2ca
1 year, 8 months ago
Selected Answer: B
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
upvoted 1 times
...
Killer44010
1 year, 8 months ago
Selected Answer: B
CrowdStrike’s Machine Learning and behavior based detections known as Indicators of Attack (IOAs)
upvoted 1 times
...
Killer44010
1 year, 8 months ago
its B, CrowdStrike’s Machine Learning and behavior based detections known as Indicators of Attack (IOAs)
upvoted 1 times
...
testmailuc
1 year, 8 months ago
Selected Answer: B
About exclusions we have: IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection. Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud. From documentation. So correct answer is B
upvoted 2 times
...
Reddington0214
1 year, 9 months ago
Selected Answer: A
When we say behavioral detection machine learning is much closer
upvoted 1 times
testmailuc
1 year, 8 months ago
You are wrong. About exclusions we have: IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection. Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud. From documentation. So correct anwser is B
upvoted 2 times
...
...
kgbac
1 year, 9 months ago
IOA exclusion ?? B
upvoted 3 times
testmailuc
1 year, 8 months ago
You are right. Just for documentation confirmation. About exclusions we have: IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection. Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud. From documentation. So correct answer is B
upvoted 2 times
...
...
ShuliAbba
1 year, 9 months ago
A is correct
upvoted 2 times
testmailuc
1 year, 8 months ago
You are wrong. About exclusions we have: IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection. Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud. From documentation. So correct answer is B
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...