CCFR-201 Exam QuestionsBrowse all questions from this exam

CCFR-201 Exam - Question 20


Which is TRUE regarding a file released from quarantine?

Show Answer
Correct Answer: BD

When a file is released from quarantine, it will not generate future machine learning detections on the associated host. This means the system will no longer flag it as a potential threat on the same host where it was initially quarantined. This allows the file to operate normally on the associated host without the interference of repeated detection.

Discussion

6 comments
Sign in to comment
Jimmy390Option: D
Nov 26, 2023

Not allowed to execute on all hosts, see Crowdstrike documentation

Pipo12345Option: D
Dec 24, 2023

I agree with D

blahman34Option: B
Jan 7, 2024

When you release a file from quarantine, it's allowed to execute on that host. Releasing a file does not affect other hosts.

sbag0024Option: D
Jan 30, 2024

D is correct for the Single host. Need to add to global policy for "all hosts"

kangaruOption: D
Feb 10, 2024

So far I've only seen all quarantined files are matched by ML PUP detection. None coming from IoA detection.

alanalanalanOption: D
May 21, 2024

agree with answer D