Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CCFA topic 1 question 12 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 12
Topic #: 1
[All CCFA Questions]

To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

  • A. Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead
  • B. Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only
  • C. Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block
  • D. Using IOC management, import the list of hashes and IP addresses and set the action to No Action
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CyberMacadamia
1 month ago
Selected Answer: A
Answer is A (However I initially thought C) - Under Endpoint Security > IOC Management > Add Indicators, you can add Hashes, Domains, and IPs. However! - IPs: You are unable to block IP addresses and can only detect or no action. - Domains: You are unable to block IP addresses and can only detect or no action.
upvoted 1 times
...
diegofretesc
6 months, 2 weeks ago
Selected Answer: A
Yo creo que la respuesta es A, ya que con IOC no se puede bloquear. Solo detectar o no tomar accion.
upvoted 1 times
...
DarkieCopy
9 months, 1 week ago
Answer is A. IOC management only allows "Detect only" and "No Action" among the possible actions. Therefore, it cannot be used to block based on IPs or domains. Custom IOA Rule groups allow to create rule types based on Network Connection (configuring a remote IP address) and domains, and gives the options to "Monitor", "Detect" and "Kill Process", being the late one the closest to "block". So, C is discarded because IOc does not block, and A might be the correct answer, despite not having a "block" option.
upvoted 2 times
...
Manuneethi
9 months, 2 weeks ago
C is Exactly Correct according to CS Falcon and there is 5 options under IOC Management to in the right side corner one buttton having : Add Hashes, Domain, IP Addresses, Import with Metadata, see Audit Log. Better before sitting for CCFA-200 Exam, verify the options under CS Console or CS Documentation.
upvoted 1 times
...
sbag0024
10 months, 2 weeks ago
Selected Answer: A
A seems correct though the IOA option in the UI is to "kill" the process. There is not a way to block.
upvoted 1 times
...
FerbOP
1 year ago
Selected Answer: A
A is correct. Custom IOA rule group can be used to block process associated with IP and domain
upvoted 2 times
...
JakeUK
1 year ago
You can add domains to IOC management but the only actions are Detect only or no action therefore the answer is A an IOA rule should be used to block it
upvoted 2 times
...
Nafil_46
1 year ago
Selected Answer: A
we can't block IP's in IOC management but we could block domains only for mobile devices. Since question is generic, Answer is A
upvoted 3 times
...
3xploit
1 year ago
Selected Answer: C
The Answer is C ! Tested in CS (Hash/Domain /IP)
upvoted 2 times
...
Belrose
1 year, 1 month ago
Selected Answer: A
The A is the right answer. The only available actions for domains and IPs are Detect only and No action, so it is not possible to prevent them. Only hashes can be blocked with the use of IOCs.
upvoted 1 times
...
im2ca
1 year, 1 month ago
Option A is the right one, you can add ip, domains and hashes in IOC's but cant take any action other then detect or No action. To block them IOA rule is required where kill process will act as a BLOCK
upvoted 2 times
...
Jer91
1 year, 1 month ago
Hello guys, it's C but on cloud EU it's not possible for IP and domain unfortunately. On US cloud yes it's possible.
upvoted 1 times
...
Prr0
1 year, 1 month ago
Checked on Falcon, Answer is C
upvoted 1 times
...
andreiushu
1 year, 2 months ago
Selected Answer: A
A is the correct answer
upvoted 1 times
...
kgbac
1 year, 2 months ago
you can't block this IP address on Falcon
upvoted 1 times
...
Reddington0214
1 year, 2 months ago
Selected Answer: A
I agree to ShuliAbba, there is no block action if you will add a domain or IP in IOC management. In IOA you can create rules for Domain or IP that could detect and Kill Process (meaning blocked)
upvoted 3 times
...
ShuliAbba
1 year, 3 months ago
Wrong!! - the correct answer is A. you can only block hashes in the IOC, the rest can be blocked via IOA.
upvoted 2 times
plantvast
1 year, 3 months ago
Actually you can add hashes, domains, and IP addresses in IOC management. The answer is C.
upvoted 4 times
plantvast
1 year, 3 months ago
Tested on Falcon.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...