nerdexam
CrowdStrike

CCFA-200B · Question #148

In order to quarantine files on the host, what prevention policy settings must be enabled?

The correct answer is B. Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be. In order to quarantine files on the host, the administrator must enable the Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" in the prevention policy settings. This will allow Falcon to quarantine malicious files and register them with Windows

Prevention Policy Configuration

Question

In order to quarantine files on the host, what prevention policy settings must be enabled?

Options

  • AMalware Protection and Custom Execution Blocking must be enabled
  • BNext-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be
  • CMalware Protection and Windows Anti-Malware Execution Blocking must be enabled
  • DBehavior-Based Threat Prevention sliders and Advanced Remediation Actions must be enabled

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    92% (44)
  • C
    2% (1)
  • D
    4% (2)

Explanation

In order to quarantine files on the host, the administrator must enable the Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" in the prevention policy settings. This will allow Falcon to quarantine malicious files and register them with Windows Security Center. The other options are either incorrect or not sufficient to enable quarantine.

Topics

#quarantine#prevention policy#Next-Gen Antivirus#Security Center Registration

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice