Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFA-200 Topic 9 Question 32 Discussion

Actual exam question for CrowdStrike's CCFA-200 exam
Question #: 32
Topic #: 9
[All CCFA-200 Questions]

You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?

Show Suggested Answer Hide Answer
Suggested Answer: D

The option that is true when a Windows host is in Reduced Functionality Mode (RFM) is that some detection patterns and preventions will not be triggered. RFM is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. When a Windows sensor is in RFM, it will only provide basic prevention capabilities, such as blocking known malware hashes and preventing script execution from the %TEMP% directory. The sensor will not send any telemetry or detection events to the Falcon platform, and will not receive any policy or update changes from the Falcon cloud. This means that some detection patterns and preventions that rely on telemetry, machine learning, or cloud analysis will not be triggered.


Contribute your Thoughts:

Robt
6 months ago
Cool, makes sense. RFM would likely keep some basic features running but not fully operational.
upvoted 0 times
...
Tegan
6 months ago
Plus, I remember reading that it affects some but not all patterns.
upvoted 0 times
...
Emeline
7 months ago
Exactly, D. It makes sense because reduced functionality impacts security features.
upvoted 0 times
...
Lorrie
7 months ago
D? Isn't that 'some detection patterns and preventions will not be triggered'?
upvoted 0 times
...
Tegan
7 months ago
Yeah, it's a tough one. I'm leaning towards D.
upvoted 0 times
...
Robt
7 months ago
Have you guys thought about the question on RFM mode for Windows hosts?
upvoted 0 times
...

Save Cancel