CrowdStrike
CCFA-200B · Question #196
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process…
The correct answer is C. Write an IOA rule to monitor process creation of .*\\remote\.exe. You've hit your limit · resets 12:50am (America/New_York)
Detection and Response
Question
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?
Options
- ACreate an exclusion for remote.exe and set a workflow to email you every time the exclusion is
- BAssign an aggressive detection level machine-learning prevention policy to the applicable hosts
- CWrite an IOA rule to monitor process creation of .*\remote.exe
- DWrite a scheduled search looking for ProcessRollup2 events for remote.exe
How the community answered
(34 responses)- A6% (2)
- B24% (8)
- C59% (20)
- D12% (4)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#custom IOA rules#process monitoring#detection engineering#regex pattern
Community Discussion
No community discussion yet for this question.