Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group.
What is the next step to disable RTR only on these hosts?
- Edit the Default Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
- Edit the Default Response Policy and add the host group to the exceptions list under "Real Time Functionality"
- Create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
- Create a new Response Policy and add the host name to the exceptions list under "Real Time Functionality"
Answer(s): C
Explanation:
The administrator can create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group that contains the servers that are not allowed to be accessed remotely. This will disable RTR only on those hosts, while keeping it enabled for the rest of the hosts. Editing the Default Response Policy or adding exceptions will not achieve the desired result.
Reference:
CrowdStrike Falcon User Guide, page 35.
Reveal Solution
Next Question