Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 5Objective 5

5.5 Configure a Containment Policy for IP Address or Subnet Exclusions That Will Apply to Network Contained Hosts Based on Security Workflow Requirements CCFA Practice Questions (Page 3)

Part of the Policy Application domain, which makes up ~17% of our current practice bank.

14questions here
3free pages
6concepts

Questions 11–14

  1. 11expert · hard

    A large enterprise is configuring a containment policy. The enterprise has a critical business application that spans multiple subnets: 10.10.1.0/24, 10.10.2.0/24, and 10.10.3.0/24. The security team wants to ensure that contained hosts can still communicate with the application during an incident. However, the team is concerned that excluding the entire 10.10.0.0/16 range would allow contained hosts to communicate with other systems on that network that should remain blocked. The team wants to minimize the scope of the exclusion while covering the application. What should the administrator configure in the containment policy?

    Select an answer first
  2. 12foundation · easy

    An administrator has added a subnet exclusion to the containment policy. What is the best way to confirm the exclusion is correctly configured?

    Select an answer first
  3. 13application · medium

    A security analyst is configuring a containment policy for a hospital network. The policy will be used to contain hosts suspected of malware infection. The hospital's patient monitoring system uses a dedicated medical device network that must remain reachable from contained hosts so that life-critical telemetry continues to flow. The medical device network uses IP addresses in the range 10.20.0.0/16. The analyst needs to ensure that contained hosts can still communicate with these devices. What should the analyst configure in the containment policy?

    Select an answer first
  4. 14expert · hard

    A Falcon administrator is troubleshooting why a contained host cannot communicate with a critical application server at 10.0.0.50. The administrator has confirmed that the IP address exclusion for 10.0.0.50 is present in the containment policy. What should the administrator check next to determine why the exclusion is not working?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.