CrowdStrike CCSE-204 - CrowdStrike Certified SIEM Engineer
What is the maximum number of active correlation rules in a CID?
Which role is most appropriate when a user only needs to view SIEM investigations and dashboards but must not modify content?
Which two tags are compliant with the CrowdStrike Parsing Standard (CPS)?
What is the primary benefit of utilizing Next-Gen SIEM’s built-in dashboards?
Which three System alerts are enabled by default in Next-Gen SIEM for third-party connectors?
Which combination of scope and permissions must be configured to create an API token that allows you to create and get the results of a query job in Next-Gen SIEM?
When setting up a data connector, which parser can be used to transform incoming data into searchable events that trigger detections in Next-Gen SIEM?
When creating an API client for Falcon SIEM Connector, which permission is required for the connector to read Falcon event streams?
An internal security team identified a small number of high-risk users. They ask you to create an app that will monitor these users and trigger an alert when specific suspicious behavior is detected.
Which Falcon feature should you use to develop this app?
In the Next-Gen SIEM Connector Dashboard, what is the maximum retention period for which you can query third-party data ingestion metrics?
