Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CrowdStrike CCFA-200b - CrowdStrike Falcon Certification Program

Page: 1 / 3
Total 100 questions

When installing the Falcon Sensor manually on Microsoft Windows, where is the installation log data stored?

A.

%LOCALAPPDATA%\Temp

B.

%SYSTEMROOT%\Temp

C.

%SYSTEMROOT%\Logs

D.

%LOCALAPPDATA%\Logs

Which report in Falcon can be used to determine the volume of blocked activity at a different prevention policy setting?

A.

Falcon Prevention Policy Debug

B.

Machine Learning Prevention Monitoring

C.

Prevention Policy Audit Trail

After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?

A.

The rule must be manually triggered

B.

Hosts must be individually selected to apply to the rule

C.

The rule group must be assigned to a prevention policy

Why would you add IP addresses to a containment policy?

A.

You want to automate the Network Containment process based on the IP address of a host

B.

A new group of analysts need to be able to place hosts under Network Containment

C.

Your organization has resources that need to be accessible when hosts are network contained

D.

Your organization has additional IP addresses that need to be able to access the Falcon console

What are the two automated triggers that cause a Fusion SOAR workflow to run?

A.

Incident and detections triggers

B.

Event and scheduled triggers

C.

Condition and action triggers

D.

Event and action triggers

What is true about User Accounts created by the Falcon Administrator?

A.

By default, all User Accounts are created with the Falcon Analyst role

B.

All new User Accounts are created using an employee identification number

C.

All User Accounts must start with the domain identifier and number

D.

All User Accounts must be created with an email address from the list of approved domains

A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

A.

Create a Containment Policy that allow lists the FQDN of your patch management tools

B.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

C.

Adjust the Content Update Policies to Early Access with No Delay

D.

Create an IP group in IP Allowlist Management

A Falcon Administrator is unable to initiate a Real-Time Response (RTR) session. What is the most likely cause?

A.

The domain controller is preventing the connection

B.

The host has a user logged into it

C.

There is another analyst connected into it

D.

They do not have an RTR role assigned to them

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

B.

Implement an SVE on the particular host

C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done

D.

Use Real Time Response to kill the offending process on the server

You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?

A.

Create a static group with the assignment rule criteria set to OS Type Workstation

B.

Create a dynamic group with the assignment rule criteria set to OS Type Workstation

C.

Create a static group with the assignment rule criteria for OS Version set to Windows 10

D.

Create a dynamic group with the assignment rule criteria for OS Version set to Windows 10