CrowdStrike Certified Falcon Administrator CCFA-200 Question # 16 Topic 2 Discussion

CrowdStrike Certified Falcon Administrator CCFA-200 Question # 16 Topic 2 Discussion

CCFA-200 Exam Topic 2 Question 16 Discussion:
Question #: 16
Topic #: 2

Which statement is TRUE regarding disabling detections on a host?


A.

Hosts with detections disabled will not alert on blocklisted hashes or machine learning detections, but will still alert on lOA-based detections. It will remain that way until detections are enabled again


B.

Hosts with detections disabled will not alert on anything until detections are enabled again


C.

Hosts with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed


D.

Hosts cannot have their detections disabled individually


Get Premium CCFA-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.