in documentation under configuring your containment policy it says: "on the containment policy page, you can allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained"
In Falcon, Containment Policies are used to define IP allowlists that specify which external systems (by IP address) a contained host can still communicate with. This is essential for maintaining access to patch management servers, SIEMs, or other critical infrastructure during containment.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CCFA Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
aN0omY
1 week, 4 days agoCiscoNoahexamtopic
1 week, 4 days ago