CCCS-203B · Question #22
Which CrowdStrike Falcon capability is most effective for identifying suspicious or malicious network connections initiated by workloads in a runtime environment?
The correct answer is C. Real-Time Network Monitoring with Behavioral Analytics. Option A: Relying solely on inbound traffic blacklists limits the scope of protection. Many malicious activities, such as data exfiltration or beaconing, involve outbound connections. Option B: Periodic audits can identify misconfigurations but lack the ability to detect or respo
Question
Which CrowdStrike Falcon capability is most effective for identifying suspicious or malicious network connections initiated by workloads in a runtime environment?
Options
- AIP Blacklist Integration for Inbound Traffic Only
- BScheduled Audits of Network Configurations
- CReal-Time Network Monitoring with Behavioral Analytics
- DNetwork Threat Detection in Development Pipelines
How the community answered
(52 responses)- A8% (4)
- B2% (1)
- C87% (45)
- D4% (2)
Explanation
Option A: Relying solely on inbound traffic blacklists limits the scope of protection. Many malicious activities, such as data exfiltration or beaconing, involve outbound connections. Option B: Periodic audits can identify misconfigurations but lack the ability to detect or respond to real-time network activity or emerging threats. Option C: CrowdStrike Falcon provides real-time monitoring and behavioral analytics to detect abnormal network activity in runtime environments. This feature allows security teams to identify and investigate malicious connections based on patterns or anomalies in communication, such as unusual ports, destinations, or traffic volumes. Option D: While development pipeline scanning is useful for ensuring secure code and configurations, it does not address runtime network behavior or connections initiated by running
Topics
Community Discussion
No community discussion yet for this question.