IOA Exclusion says - Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Source: https://falcon.crowdstrike.com/documentation/68/detection-and-prevention-policies#exclusions
I think the A option is the correct answer.
In IOA actions you can not avoid the detection, you only can monitor, detect or mitigate in any way (Kill process, Block Execution) so it is not possible to hide the detection.
In relation with the IOAs are applied to all the detections in general not only for behavioural detection, so the Machine Learning is the only choice that is related with only behavioural detections, and finally with machine learning detections it is possible avoid the detection and prevention, so I think the most logical answer is A.
About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
You are wrong. About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct anwser is B
You are right. Just for documentation confirmation.
About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
You are wrong. About exclusions we have:
IOA: Stop all behavioral detections and preventions for an IOA that’s based on a CrowdStrike-generated detection.
Machine learnings: For trusted file paths, stop all ML-based detections and preventions, or stop files from being uploaded to the CrowdStrike cloud.
From documentation.
So correct answer is B
upvoted 2 times
...
...
This section is not available anymore. Please use the main Exam Page.CCFA Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
GreenHok
9Â months, 3Â weeks agoGapsiux
1Â year, 3Â months agoManuneethi
1Â year, 9Â months agoAlex_41
1Â year, 11Â months agoMSKid
1Â year, 11Â months agoxart
2Â years agoFerbOP
2Â years agokgmangle
2Â years, 1Â month agoBelrose
2Â years, 1Â month agoim2ca
2Â years, 1Â month agoKiller44010
2Â years, 2Â months agoKiller44010
2Â years, 2Â months agotestmailuc
2Â years, 2Â months agoReddington0214
2Â years, 2Â months agotestmailuc
2Â years, 2Â months agokgbac
2Â years, 2Â months agotestmailuc
2Â years, 2Â months agoShuliAbba
2Â years, 3Â months agotestmailuc
2Â years, 2Â months ago