nerdexam
CrowdStrike

CCFA-200B · Question #76

You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best ap

The correct answer is C. Add an allowlist entry for the individual server's IP address. The best approach to updating the Containment Policy to allow a new patch server that should be reachable while hosts in your environment are network contained is to add an allowlist entry for the individual server's IP address. An allowlist entry allows you to define a list of t

Network Containment

Question

You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?

Options

  • AAdd an allowlist entry for the individual server's MAC address
  • BAdd an allowlist entry containing the host group that the server belongs to
  • CAdd an allowlist entry for the individual server's IP address
  • DAdd an allowlist entry containing CIDR notation for the /24 network the server belongs to

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    83% (29)
  • D
    9% (3)

Explanation

The best approach to updating the Containment Policy to allow a new patch server that should be reachable while hosts in your environment are network contained is to add an allowlist entry for the individual server's IP address. An allowlist entry allows you to define a list of trusted IP addresses that can communicate with your contained hosts. This way, you can isolate a host from the network while still allowing it to access essential resources or services, such as a patch server. If the server's IP address is static and does not change, adding an individual IP address is more precise and secure than adding a host group or a network range.

Topics

#Network Containment#containment policy#IP allowlist#patch server access

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice