CCFA-200B · Question #107
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is…
The correct answer is C. Create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy. The administrator can create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group that contains the servers that are not allowed to be accessed remotely. This will disable RTR only on those hosts, while keeping it enabled for…
Question
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?
Options
- AEdit the Default Response Policy, toggle the "Real Time Response" switch off and assign the
- BEdit the Default Response Policy and add the host group to the exceptions list under "Real Time
- CCreate a new Response Policy, toggle the "Real Time Response" switch off and assign the policy
- DCreate a new Response Policy and add the host name to the exceptions list under "Real Time
How the community answered
(37 responses)- A8% (3)
- B5% (2)
- C84% (31)
- D3% (1)
Explanation
The administrator can create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group that contains the servers that are not allowed to be accessed remotely. This will disable RTR only on those hosts, while keeping it enabled for the rest of the hosts. Editing the Default Response Policy or adding exceptions will not achieve the
Topics
Community Discussion
No community discussion yet for this question.