CCFA-200B · Question #110
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be store
The correct answer is D. Machine Learning Exclusions. Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment. The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested f
Question
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
Options
- AUSB Device Policy
- BFirewall Rule Group
- CContainment Policy
- DMachine Learning Exclusions
How the community answered
(44 responses)- A2% (1)
- B14% (6)
- C7% (3)
- D77% (34)
Explanation
Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment. The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested folder with a GLOB expression.
Topics
Community Discussion
No community discussion yet for this question.