Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFA-200 Topic 5 Question 53 Discussion

Actual exam question for CrowdStrike's CCFA-200 exam
Question #: 53
Topic #: 5
[All CCFA-200 Questions]

On the Host management page which filter could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform?

Show Suggested Answer Hide Answer
Suggested Answer: A

Turn on the Script-Based Execution Monitoring prevention policy setting to enable the 'Falcon sensor to monitor the contents of scripts and shells that are popular mechanisms for executing malicious code on hosts. This setting does not kill or block scripts.'

Scripting languages:

Excel 4.0 macros

JScript

VBA Macros

VBScript

The Sensor Visibility setting that should be turned on within the Prevention policy settings to monitor suspicious VBA macros is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. VBA (Visual Basic for Applications) is a scripting language that can be embedded in Microsoft Office documents, such as Word or Excel. VBA macros can be used to automate tasks or perform actions within the documents, but they can also be abused by attackers to deliver malware or execute malicious code. Script-based Execution Monitoring can help detect and prevent such attacks by monitoring the contents of VBA macros for execution of malicious content.


Contribute your Thoughts:

Glendora
2 months ago
I'm going with 'Type' - it's the classic 'needle in a haystack' scenario, and 'Type' is the sharpest pitchfork you've got!
upvoted 0 times
...
Marquetta
3 months ago
'Type' is definitely the way to go here. Although I did consider 'Hostname' for a second, just to see if any of the devices were named 'WorkstationOfDoom'.
upvoted 0 times
Trina
1 months ago
Yeah, 'Type' is the most relevant filter for this search.
upvoted 0 times
...
Carlee
1 months ago
I agree, 'Type' would quickly identify all the workstations.
upvoted 0 times
...
Aleisha
2 months ago
I think 'Type' is the best filter to use.
upvoted 0 times
...
...
Luann
3 months ago
I was thinking 'Platform', but 'Type' makes way more sense. It's like searching for all the 'Fords' in a car dealership - you go straight for the model, not the brand.
upvoted 0 times
...
Darrel
3 months ago
Ooh, tricky one! I'm leaning towards 'Type' as well. Seems like the most straightforward way to isolate all the workstations.
upvoted 0 times
Edward
1 months ago
No, I think 'Type' is the best option to identify workstations.
upvoted 0 times
...
Leandro
1 months ago
I'm not sure, maybe 'Platform' could also work?
upvoted 0 times
...
Malcom
1 months ago
I agree, 'Type' seems like the most logical choice.
upvoted 0 times
...
Bok
1 months ago
I think 'Type' is the right filter to use.
upvoted 0 times
...
...
Marion
4 months ago
Hmm, I'd guess 'Type' would be the way to go. Workstations are a specific device category, so that should be the quickest filter option.
upvoted 0 times
Benton
3 months ago
Let's try using the 'Type' filter to see if it works.
upvoted 0 times
...
Benton
3 months ago
I agree, 'Type' should help us quickly identify workstations.
upvoted 0 times
...
Benton
3 months ago
I think 'Type' is the right filter to use.
upvoted 0 times
...
...
Margery
4 months ago
I think 'Platform' filter could also be used to identify 'Workstation' devices, as it specifies the platform of the device.
upvoted 0 times
...
Leonora
4 months ago
I agree with Joanne, 'Type' filter makes sense because it categorizes devices based on their type.
upvoted 0 times
...
Joanne
4 months ago
I think the filter 'Type' could be used to quickly identify all devices categorized as a 'Workstation'.
upvoted 0 times
...

Save Cancel