CCFA Exam QuestionsBrowse all questions from this exam

CCFA Exam - Question 17


Which of the following applies to Custom Blocking Prevention Policy settings?

Show Answer
Correct Answer: A

Hashes must be entered on the Prevention Hashes page before they can be blocked via this policy. Custom blocking in prevention policies refers to blocklisting hashes through the IOC Management, and hashes need to be added here first. There is no mention of blocklisting IP addresses and domains under custom blocking settings, nor the necessity for remediation after partial executions.

Discussion

12 comments
Sign in to comment
kgbacOption: C
Feb 15, 2023

Prevention policies don't block custom IOC management you can add link to custom IOA rules. That mean C is the correct answer.

testmailuc
Mar 9, 2023

https://www.crowdstrike.com/blog/tech-center/how-to-prevent-malware-with-custom-blacklisting/

Jek88Option: C
Feb 17, 2023

C is the correct answer.

testmailuc
Mar 9, 2023

https://www.crowdstrike.com/blog/tech-center/how-to-prevent-malware-with-custom-blacklisting/

im2caOption: D
Mar 22, 2023

AUTO, N-1, N-2

3xploitOption: A
Mar 27, 2023

https://www.crowdstrike.com/blog/tech-center/how-to-prevent-malware-with-custom-blacklisting/ A for me

plantvastOption: B
Jan 20, 2023

Custom blocking in prevention policies referes to hashes, ips, and domains added to IOC Management.

ShuliAbbaOption: A
Jan 24, 2023

@plantvast - I think you might be wrong because you cannot block IPs and domains, only hashes in the IOC + as written in the policy section "Block processes matching hashes that you add to IOC Management with the action set to "Block" or "Block, hide detection".

plantvast
Jan 26, 2023

You can actually add hashes, domains and IP addresses on IOC management. Navigate to the page in Falcon and attempt to a new indicator and the options will appear.

ShuliAbba
Jan 28, 2023

you are right and wrong my friend, adding IPs and domains in the IOC is indeed possible, but not with "block" action on them - only "detect" or "no action".

ShuliAbba
Jan 28, 2023

from the "Custom Blocking" policy section - "Block processes matching hashes that you add to IOC Management with the action set to "Block" or "Block, hide detection".

testmailucOption: A
Mar 9, 2023

Check here: https://www.crowdstrike.com/blog/tech-center/how-to-prevent-malware-with-custom-blacklisting/

FerbOPOption: C
Apr 25, 2023

C is correct - Block processes matching hashes that you add to IOC Management with action Block

MSKidOption: A
May 30, 2023

Sounds like A to me: Falcon allows you to upload hashes from your own black or white lists. To enabled this navigate to the Configuration App, Prevention hashes window, and click on “Upload Hashes” in the upper right-hand corner. Note that you can also automate the task of importing hashes with the CrowdStrike Falcon® API.

sbag0024Option: C
Jun 14, 2023

C? bad question imo.

ManuneethiOption: A
Jul 16, 2023

A is correct : Custom Blocking enables blocklisting by hash, via hashes you add to IOC Management with the option set to Block.

diegofretescOption: A
Oct 10, 2023

A is correct