CrowdStrike CCSE-204 - CrowdStrike Certified SIEM Engineer
What is the purpose of labels in Fleet Management?
How can you enable internal logging for a specific Falcon Log Collector instance from the Fleet view?
An event has the following fields:

Which CQL query will output the frequency of a unique set of ComputerName, UserName, CommandLine?
A correlation rule is generating a high volume of detections. You have been asked to temporarily deactivate it so your team can investigate.
What will happen to previously generated detections while the rule is in a deactivated state?
You notice a larger than expected ingest delay from one of your high-volume streaming log collectors.
Which setting should you increase on the log collector to improve performance?
You find a Falcon Log Collector instance on a Linux system that is not connected to Fleet Management.
What command would you use to enroll the Falcon Log Collector?
A Falcon Log Collector has been configured with 4 sinks of type memory, each having a queue size of 2GB.
What is the minimum memory requirement produced by this configuration?
