nerdexam
CrowdStrike

CCCS-203B · Question #218

You are creating a custom Indicator of Maliciousness (IOM) rule in CrowdStrike Falcon to block access to a specific malicious domain. Which of the following steps is correct for ensuring the IOM…

The correct answer is A. Select the "Domain Name" condition type and specify the domain to block. Option A: This is correct because using the "Domain Name" condition type allows you to specify a particular domain as the target for the IOM rule. This ensures that CrowdStrike monitors and blocks activities related to the specified domain. Proper configuration of the condition…

Threat Detection and Prevention

Question

You are creating a custom Indicator of Maliciousness (IOM) rule in CrowdStrike Falcon to block access to a specific malicious domain. Which of the following steps is correct for ensuring the IOM rule functions effectively?

Options

  • ASelect the "Domain Name" condition type and specify the domain to block.
  • BUse the "File Hash" condition type to specify the domain's IP address.
  • CAdd the domain to the Global Allowlist to ensure it is blocked.
  • DAssign the IOM rule a severity level of "Informational" to ensure it blocks the domain.

How the community answered

(52 responses)
  • A
    75% (39)
  • B
    6% (3)
  • C
    4% (2)
  • D
    15% (8)

Explanation

Option A: This is correct because using the "Domain Name" condition type allows you to specify a particular domain as the target for the IOM rule. This ensures that CrowdStrike monitors and blocks activities related to the specified domain. Proper configuration of the condition type is essential for the rule to function as intended. Option B: This is incorrect because "File Hash" is designed for identifying specific files based on their hash values, not for blocking domains or IP addresses. Using this type would result in an ineffective rule for domain blocking. Option C: This is incorrect because the Allowlist is used to exclude entities from being flagged or blocked by CrowdStrike. Adding a domain to the Allowlist would prevent it from being blocked. Option D: This is incorrect because severity levels such as "Informational" are used for categorizing the criticality of events, not for determining whether a rule will block activity. For blocking, the rule's action type must explicitly include "Block."

Topics

#IOM rule#custom indicators#domain blocking#threat intelligence

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice