Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 6Objective 3

6.3 Assess IOC Settings Required for Customized Security Posturing and to Manage False Positives CCFA Practice Questions (Page 5)

Part of the Rules Configuration domain, which makes up ~13% of our current practice bank.

21questions here
5free pages
4concepts

Questions 21–21

  1. 21expert · hard

    A large organization has a custom IOC rule for a known APT group's infrastructure. The rule is set to 'Block' and applies to all endpoints. The security team discovers that the rule is blocking a legitimate cloud storage service that shares an IP address with the APT infrastructure. The service is used by the marketing department for daily operations. The team needs to restore service quickly while maintaining the rule's protection for the rest of the organization. What is the best approach?

    Select an answer first
Finished these 1 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.