CrowdStrike Certified Falcon Administrator (CCFA) — Question 153

Which statement is TRUE regarding disabling detections on a host?

Answer options

Correct answer: B

Explanation

The correct answer is B because once detections are disabled, the host will not generate any alerts until detections are re-enabled. Option A is incorrect as it misstates the alerting behavior. Option C incorrectly suggests that some alerts would still occur, and option D is wrong because it is indeed possible to disable detections on individual hosts.