CrowdStrike CCFA-200b - CrowdStrike Falcon Certification Program
You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?
What are the three required parts of a Fusion SOAR workflow condition?
During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?
You are tasked with creating a “Workstations†host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?
You need to be aware of which policies are the most used as new hosts are being added to your CID. Where will you find a review of the top-ten sensor update, prevention, and device control policies?
You want to add an additional layer of security to high-risk Real Time Response commands for your environment. Where do you configure MFA for RTR within the UI?
What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?
Which report would show you an overview of the top ten most-applied policies by sensors in your environment?
Your incident responder team is migrating existing workflows into Fusion SOAR workflows so that they execute natively in Falcon. The workflow imports are failing. What format must the workflows be in order to successfully import them into Fusion SOAR?
Which role allows a Falcon user to create Real Time Response Custom Scripts?
