nerdexam
CrowdStrike

CCFA-200B · Question #110

One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be store

The correct answer is D. Machine Learning Exclusions. Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment. The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested f

Prevention Policies and Exclusions

Question

One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?

Options

  • AUSB Device Policy
  • BFirewall Rule Group
  • CContainment Policy
  • DMachine Learning Exclusions

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    14% (6)
  • C
    7% (3)
  • D
    77% (34)

Explanation

Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment. The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested folder with a GLOB expression.

Topics

#ML exclusions#false positives#file path exclusion#prevention tuning

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice