CrowdStrike
CCFA-200B · Question #226
Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What…
The correct answer is C. Temporarily disable detections for the server in Host Management and re-enable after the test is. You've hit your limit · resets 12:50am (America/New_York)
Detection Management
Question
Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?
Options
- ADelete the detections in the console and contain the server undergoing the test
- BPermanently disable detections for the server in Host Management
- CTemporarily disable detections for the server in Host Management and re-enable after the test is
- DCreate a Fusion Workflow to email the SOC team every time the penetration test generates a
How the community answered
(35 responses)- A6% (2)
- B3% (1)
- C80% (28)
- D11% (4)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#detection management#penetration testing#detection suppression#host management
Community Discussion
No community discussion yet for this question.