What prevention policy settings must be enabled to quarantine files on the host?
A.
Quarantine Files; Windows Anti-Malware Execution Blocking
B.
Malware Protection; Custom Execution Blocking
C.
Next-Gen Antivirus Prevention sliders; Quarantine & Security Center Registration
D.
Advanced Remediation Actions; Quarantine level set to Aggressive
The Answer Is:
C
This question includes an explanation.
Explanation:
To quarantine files, Falcon requires the relevant Next-Gen Antivirus prevention capability and the quarantine setting. The correct pairing is Next-Gen Antivirus Prevention sliders with Quarantine & Security Center Registration . Quarantine does not operate independently; Falcon must first prevent the file through NGAV-related controls such as cloud or sensor machine-learning prevention. Once prevention occurs, the quarantine setting governs whether the prevented executable is quarantined on the host. Custom Execution Blocking is related to IOC-based blocking, not the general NGAV quarantine requirement. “Advanced Remediation Actions” and an “Aggressive quarantine level” are not the documented configuration pair. The course guide identifies quarantine under Next-Gen Antivirus and ties it to prevention-level configuration and Security Center registration.
CCFA-200b PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"