nerdexam
CrowdStrike

CCFA-200B · Question #196

Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process…

The correct answer is C. Write an IOA rule to monitor process creation of .*\\remote\.exe. You've hit your limit · resets 12:50am (America/New_York)

Detection and Response

Question

Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?

Options

  • ACreate an exclusion for remote.exe and set a workflow to email you every time the exclusion is
  • BAssign an aggressive detection level machine-learning prevention policy to the applicable hosts
  • CWrite an IOA rule to monitor process creation of .*\remote.exe
  • DWrite a scheduled search looking for ProcessRollup2 events for remote.exe

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    24% (8)
  • C
    59% (20)
  • D
    12% (4)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#custom IOA rules#process monitoring#detection engineering#regex pattern

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice