CCFA Exam QuestionsBrowse all questions from this exam

CCFA Exam - Question 71


Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?

Show Answer
Correct Answer: C

Real-time offline protection is a feature found only with sensor-based machine learning. While other features can also be achieved through various methods, real-time offline protection specifically relies on the local sensor's capability to work without an active internet connection, which is unique to sensor-based ML systems.

Discussion

18 comments
Sign in to comment
VJJijo
Feb 3, 2023

C should be correct

Roy_SoOption: C
Feb 6, 2023

Correct should be C after revisit the doc. Provides machine learning-based on-sensor AV protection for malicious files, including offline protection.

bbqsauceomgOption: C
Mar 5, 2023

only sensor base include offline Sensor Anti-malware For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware. About levels

FerbOPOption: C
Apr 26, 2023

C is correct

andreiushuOption: D
Feb 16, 2023

For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware

Prr0
Mar 8, 2023

C is correct, check falcon console > Next-Gen Antivirus, Sensor Machine Learning only appear Sensor Anti-malware

LaCubanitaOption: D
May 3, 2023

It should be D, the only option within the Sensor Machine Learning section is Sensor Anti-malware (Detection & Prevention) and it reads: "For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware. That's basically what option D is

sbag0024Option: C
Jun 9, 2023

Going with C. The policy says " For offline and online hosts"

sbag0024Option: C
Jun 14, 2023

C is correct as it is for offline

Brian9296Option: D
Oct 9, 2023

It's mentioned in the console, "For offline and online hosts.....". So the answer shouldn't be "C". ==================================================== Sensor Anti-malware For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware. About levels

Roy_SoOption: A
Feb 2, 2023

A is the correct answer

testmailucOption: D
Mar 3, 2023

I would go with D. After checking the documentation i found this "or unknown and zero-day threats, Falcon applies IOA detection, using machine learning techniques to build predictive models that can detect never-before-seen malicious activities with high accuracy." ChatGPT also confirms it and some online resources

Dave071
Apr 4, 2023

Answer is D. "For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware."

TommyJ111Option: D
Jun 29, 2023

D is correct. Says right in the setting "...use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware.

DarkieCopyOption: D
Jul 24, 2023

According to documentation (documentation/detections/technique/sensor-based-ml-cst0007): CrowdStrike sensor-based machine learning (ML) identifies and analyzes unknown executables as they run on hosts. This technique is triggered by files and file attributes associated with known malware. This is similar to the [Cloud-based ML](/support/documentation/detections/technique/cloud-based-ml) technique. Cloud-based ML is informed by global analysis of executables that classifies and identifies malware. The key difference is that it doesn't run on hosts when they're offline. Therefore it is D. Sensor-based ML does not run on hosts when they are offline, discarding C.

sadevek
Jul 5, 2024

In the prevention policy its clearly mentioned that " FOR OFFLINE AND ONLINE HOSTS" - "For offline and online hosts, use sensor-based machine learning to identify and analyze unknown executables as they run to detect and prevent malware.", so the answer should be D

evilCorpBot7494Option: D
Dec 3, 2024

The unkown executables and zero days is the whole purpose of applying Machine Learning to threat detection in cybersecurity. Offline protection should still be had by all modules, otherwise CS would be a very bad solution if it only protects from your blacklisted hashes when you have internet. Answer is D.

EA88Option: C
Mar 19, 2025

Sensor-based Machine Learning (ML) in CrowdStrike Falcon leverages machine learning capabilities directly on the endpoint, allowing the Falcon sensor to provide real-time protection even when the endpoint is offline (i.e., not connected to the internet). This offline protection is a key feature of sensor-based ML, as it enables the detection and blocking of malicious activities locally on the endpoint, without needing constant communication with the cloud.