Exam CCFA-200b Topic 1 Question 210 Discussion
Actual exam question for CrowdStrike's CCFA-200b exam
Question #: 210
Topic #: 1
Question #: 210
Topic #: 1
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
Suggested Answer: A Vote an answer
The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error.
by Moses at Mar 20, 2026, 06:03 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).