CCFA-200B · Question #156
Why would you use the Prevention Policy Debug Report?
The correct answer is C. To confirm that prevention policy settings were applied to a host. The Prevention Policy Debug Report is specifically designed to verify that prevention policy settings were successfully applied to a particular host - confirming the host is actually running the configured policy configuration (C). Option A is wrong because policy precedence is…
Question
Why would you use the Prevention Policy Debug Report?
Options
- ATo confirm that prevention policy precedence was applied to hosts
- BTo confirm the number of detections on a host
- CTo confirm that prevention policy settings were applied to a host
- DTo confirm the number of host groups to which a policy was applied
How the community answered
(27 responses)- A7% (2)
- C89% (24)
- D4% (1)
Explanation
The Prevention Policy Debug Report is specifically designed to verify that prevention policy settings were successfully applied to a particular host - confirming the host is actually running the configured policy configuration (C). Option A is wrong because policy precedence is a separate concern handled by policy ordering/priority views, not the debug report. Option B is wrong because detection counts are tracked in detection dashboards or event logs, not a policy debug report. Option D is wrong because host group membership and policy scope are managed in the policy assignment interface, not a debug report.
Memory tip: Think of "debug" as troubleshooting application of settings - when something isn't working as expected, you use the Debug Report to confirm the policy settings landed correctly on the host, not to count events or check assignments.
Topics
Community Discussion
No community discussion yet for this question.