exam questions

Exam CCFA All Questions

View all questions & answers for the CCFA exam

Exam CCFA topic 1 question 68 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 68
Topic #: 1
[All CCFA Questions]

You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?

  • A. Prevention Policy Audit Trail
  • B. Prevention Policy Debug
  • C. Prevention Hashes Ignored
  • D. Machine-Learning Prevention Monitoring
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sbag0024
11 months ago
Selected Answer: D
D is the only answer. Also checked in the console
upvoted 1 times
...
Belrose
1 year, 1 month ago
Selected Answer: D
D is the correct answer, tested in console. Audit logs --> Machine-learning prevention monitoring It shows the count of ML expected detections based on the detection levels for a defined time period and the list of files that would be detected on each detection level.
upvoted 2 times
...
bbqsauceomg
1 year, 2 months ago
answer should be D here is what it does Machine-Learning Prevention Monitoring Use this dashboard to view malware that would have been blocked in your environment over the selected timeframe based on different Machine Learning Prevention settings (Cautious, Moderate, Aggressive or Extra Aggressive).
upvoted 2 times
...
Jek88
1 year, 2 months ago
Selected Answer: D
D is the correct answer.
upvoted 2 times
...
VJJijo
1 year, 3 months ago
D IS CORRECT
upvoted 3 times
...
Roy_So
1 year, 3 months ago
Selected Answer: C
Only Machine-Learning Prevention Monitoring.
upvoted 1 times
...
shemilandia
1 year, 3 months ago
I asked chatGPT "explain me Prevention Policy Debug dashboard reports on Crowdstrike console" a/ It displays data on events that triggered security policies, such as blocked and allowed events, and the specific policy rule that was applied. This report allows administrators to evaluate the effectiveness of their security policies and make adjustments as necessary to improve the platform's overall security posture.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago