nerdexam
CrowdStrike

CCFA-200B · Question #69

What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?

The correct answer is A. Deep packet inspection. The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep pack

Sensor Deployment and Management

Question

What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?

Options

  • ADeep packet inspection
  • BLinux Sub-System
  • CPowerShell
  • DWindows Proxy

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    4% (1)
  • C
    8% (2)

Explanation

The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error.

Topics

#deep packet inspection#firewall configuration#MITM protection#network requirements

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice