Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFA-200 Topic 2 Question 50 Discussion

Actual exam question for CrowdStrike's CCFA-200 exam
Question #: 50
Topic #: 2
[All CCFA-200 Questions]

You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?

Show Suggested Answer Hide Answer
Suggested Answer: D

The option that is true when a Windows host is in Reduced Functionality Mode (RFM) is that some detection patterns and preventions will not be triggered. RFM is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. When a Windows sensor is in RFM, it will only provide basic prevention capabilities, such as blocking known malware hashes and preventing script execution from the %TEMP% directory. The sensor will not send any telemetry or detection events to the Falcon platform, and will not receive any policy or update changes from the Falcon cloud. This means that some detection patterns and preventions that rely on telemetry, machine learning, or cloud analysis will not be triggered.


Contribute your Thoughts:

Lisandra
2 days ago
Ah, this is a tough one. I'm torn between B and D, but I think D is the winner. Gotta love these Windows quirks, am I right?
upvoted 0 times
...
Katina
3 days ago
I agree with Felicidad. In Reduced functionality mode, some detection patterns and preventions will not be triggered.
upvoted 0 times
...
Lashawna
5 days ago
Haha, I bet the correct answer is C. Prevention patterns not triggering? That sounds about right for a reduced functionality scenario. Wish they'd just let the system run at full power.
upvoted 0 times
...
Stephaine
7 days ago
I'm going with B. If the system is in reduced mode, event reporting is probably going to be off the table. Gotta love these tricky Windows modes!
upvoted 0 times
...
Felicidad
13 days ago
I think the answer is D.
upvoted 0 times
...
Ben
13 days ago
Hmm, I think D is the correct answer. The reduced functionality mode definitely impacts some detection and prevention patterns, so that one makes the most sense.
upvoted 0 times
Gayla
3 days ago
User2: Yeah, that's true. It's important to be aware of the limitations in RFM.
upvoted 0 times
...
Bernardo
6 days ago
User1: I think D is correct too. RFM affects some detection and prevention patterns.
upvoted 0 times
...
...

Save Cancel