nerdexam
CrowdStrike

CCFA-200B · Question #21

You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to…

The correct answer is C. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then. The best way to ensure that a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers are not allowed to run in your environment is to use IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then…

Prevention Policy and IOC Management

Question

You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?

Options

  • AUsing the Support Portal, create a support ticket and include the list of binary hashes, asking
  • BUsing Custom Alerts in the Investigate App, create a new alert using the template "Process
  • CUsing IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then
  • DUsing the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them,

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    80% (37)
  • D
    11% (5)

Explanation

The best way to ensure that a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers are not allowed to run in your environment is to use IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking. This will allow Falcon to block the execution of these hashes on the hosts using this policy. The other options are either incorrect or not efficient to achieve this goal.

Topics

#IOC Management#hash blocking#SHA256#malware prevention

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice