Exam CCFR-201 All QuestionsBrowse all questions from this exam
Question 20

Which is TRUE regarding a file released from quarantine?

    Correct Answer: D

    When a file is released from quarantine, it will not generate future machine learning detections on the associated host. This means the system will no longer flag it as a potential threat on the same host where it was initially quarantined. This allows the file to operate normally on the associated host without the interference of repeated detection.

Discussion
Jimmy390Option: D

Not allowed to execute on all hosts, see Crowdstrike documentation

Pipo12345Option: D

I agree with D

alanalanalanOption: D

agree with answer D

kangaruOption: D

So far I've only seen all quarantined files are matched by ML PUP detection. None coming from IoA detection.

sbag0024Option: D

D is correct for the Single host. Need to add to global policy for "all hosts"

blahman34Option: B

When you release a file from quarantine, it's allowed to execute on that host. Releasing a file does not affect other hosts.