Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CrowdStrike Falcon Certification Program CCFA-200b Question # 16 Topic 2 Discussion

CrowdStrike Falcon Certification Program CCFA-200b Question # 16 Topic 2 Discussion

CCFA-200b Exam Topic 2 Question 16 Discussion:
Question #: 16
Topic #: 2

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?


A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection


B.

Implement an SVE on the particular host


C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done


D.

Use Real Time Response to kill the offending process on the server


Get Premium CCFA-200b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.