nerdexam
CrowdStrike

CCFA-200B · Question #163

After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?

The correct answer is B. The rule group must be assigned to one or more prevention policies. Enabling an IOA rule and its rule group is necessary but not sufficient - the rule group must be assigned to one or more prevention policies before it will actually apply to any endpoints. Prevention policies are the mechanism CrowdStrike Falcon uses to bind…

Detection and Response

Question

After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?

Options

  • ANothing else needs to be done; the rule should start working
  • BThe rule group must be assigned to one or more prevention policies
  • CThe rule needs to be manually triggered to ensure it works as intended
  • DYou must individually select which hosts you would like to apply to rule to

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    88% (21)
  • D
    4% (1)

Explanation

Enabling an IOA rule and its rule group is necessary but not sufficient - the rule group must be assigned to one or more prevention policies before it will actually apply to any endpoints. Prevention policies are the mechanism CrowdStrike Falcon uses to bind detection/prevention logic to specific groups of hosts, so without this assignment step, the rule group simply floats unattached and has no effect.

Why the distractors are wrong:

  • A is incorrect because the rule group is inert until linked to a policy - enabling alone doesn't deploy it.
  • C is incorrect because IOA rules are event-driven and trigger automatically on matching activity; there's no manual trigger step.
  • D is incorrect because host targeting is handled at the policy level (via host groups), not by selecting individual hosts per rule.

Memory tip: Think of it as a three-layer stack - Rule → Rule Group → Prevention Policy. The policy is the "last mile" that connects your rules to real hosts. If any layer in the stack is missing or disconnected, nothing reaches the endpoint.

Topics

#IOA rules#rule groups#prevention policy assignment#policy activation

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice