Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CrowdStrike CCFA-200b - CrowdStrike Falcon Certification Program

Page: 2 / 3
Total 100 questions

You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?

A.

Platform

B.

OS version

C.

Type

D.

OU

What are the three required parts of a Fusion SOAR workflow condition?

A.

Operator, value, and source

B.

Alert, action, and schedule

C.

Trigger, parameter, and alert

D.

Parameter, operator, and value

During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?

A.

Put-and-Run is not enabled in the response policy

B.

Custom Scripts is not enabled in the response policy

C.

Script-Based Execution Monitoring is not enabled in the prevention policy

D.

The responder requires the RTR Administrator role

You are tasked with creating a “Workstations” host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?

A.

OU Workstation

B.

Grouping Tags Workstation

C.

Type: Workstation

D.

Platform Windows

You need to be aware of which policies are the most used as new hosts are being added to your CID. Where will you find a review of the top-ten sensor update, prevention, and device control policies?

A.

Executive Summary

B.

Sensor Policy Daily report

C.

Managed Assets dashboard

You want to add an additional layer of security to high-risk Real Time Response commands for your environment. Where do you configure MFA for RTR within the UI?

A.

General settings

B.

Notifications

C.

Response policies

D.

Containment policy

What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?

A.

It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

B.

It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

C.

It is designed to show malicious processes that would have been blocked in your environment based on different Machine-Learning Prevention settings

D.

It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

Which report would show you an overview of the top ten most-applied policies by sensors in your environment?

A.

Scheduled reports

B.

Sensor report dashboard

C.

Executive summary

D.

Sensor policy daily report

Your incident responder team is migrating existing workflows into Fusion SOAR workflows so that they execute natively in Falcon. The workflow imports are failing. What format must the workflows be in order to successfully import them into Fusion SOAR?

A.

YAML

B.

CSV

C.

SOAR

D.

JSON

Which role allows a Falcon user to create Real Time Response Custom Scripts?

A.

Real Time Responder – Active Responder

B.

Real Time Responder – Administrator

C.

Real Time Responder – Read Only Analyst

D.

Real Time Responder – Script Developer