Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CrowdStrike Falcon Certification Program CCFA-200b Question # 14 Topic 2 Discussion

CrowdStrike Falcon Certification Program CCFA-200b Question # 14 Topic 2 Discussion

CCFA-200b Exam Topic 2 Question 14 Discussion:
Question #: 14
Topic #: 2

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to “C:\Users\Bob\DevCode\felix.dll”. In the detection, you see that it is triggering only on a specific Falcon IOA. What would be the best course of action for this situation?


A.

Create an IOA exclusion for “C:\Users\Bob\DevCode\felix.dll”


B.

Create a Custom IOC and set it to “Allow” for “C:\Users\Bob\DevCode\felix.dll”


C.

Manually turn off the built-in IOA through prevention policies


D.

Create a sensor visibility exclusion for “C:\Users\Bob\DevCode\felix.dll”


Get Premium CCFA-200b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.