Câu 29: CCFA-200B: CrowdStrike Certified Falcon Administrator
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?
Nội dung câu hỏi
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Write an IOA rule to monitor process creation of .*\\remote\.exe — đáp án hiện tại
- B. Create an exclusion for remote.exe and set a workflow to email you every time the exclusion is used
- C. Write a scheduled search looking for ProcessRollup2 events for remote.exe
- D. Assign an aggressive detection level machine-learning prevention policy to the applicable hosts
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.