CrowdStrike CCFA-200b - CrowdStrike Falcon Certification Program
When installing the Falcon Sensor manually on Microsoft Windows, where is the installation log data stored?
Which report in Falcon can be used to determine the volume of blocked activity at a different prevention policy setting?
After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?
Why would you add IP addresses to a containment policy?
What are the two automated triggers that cause a Fusion SOAR workflow to run?
What is true about User Accounts created by the Falcon Administrator?
A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?
A Falcon Administrator is unable to initiate a Real-Time Response (RTR) session. What is the most likely cause?
Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?
You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?
