CCFA-200B · Question #137
When editing an existing IOA exclusion, what can NOT be edited?
The correct answer is A. The IOA name. When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry e
Question
When editing an existing IOA exclusion, what can NOT be edited?
Options
- AThe IOA name
- BAll parts of the exclusion can be changed
- CThe exclusion name
- DThe hosts groups
How the community answered
(24 responses)- A96% (23)
- C4% (1)
Explanation
When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as "Suspicious Process Execution - Script Interpreter Executing File". The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform. However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria.
Topics
Community Discussion
No community discussion yet for this question.