| Exam Name: | CrowdStrike Falcon Certification Program | ||
| Exam Code: | CCFA-200b Dumps | ||
| Vendor: | CrowdStrike | Certification: | CrowdStrike Falcon Certification Program |
| Questions: | 100 Q&A's | Shared By: | maximillian |
Which ML exclusion pattern would be the most accurate for all .exe binaries in “C:\Program Files\Software\”, including any subfolders of Software?
During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?
You need to be aware of which policies are the most used as new hosts are being added to your CID. Where will you find a review of the top-ten sensor update, prevention, and device control policies?