Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CrowdStrike CCSE-204 - CrowdStrike Certified SIEM Engineer

Page: 1 / 2
Total 62 questions

What is the maximum number of active correlation rules in a CID?

A.

1000

B.

250

C.

750

D.

500

Which role is most appropriate when a user only needs to view SIEM investigations and dashboards but must not modify content?

A.

NG SIEM Administrator

B.

NG SIEM Security Lead

C.

NG SIEM Analyst

D.

NG SIEM Analyst – Read Only

Which two tags are compliant with the CrowdStrike Parsing Standard (CPS)?

A.

#event.type and #event.kind

B.

#vendor.name and #event.type

C.

#observer.type and #event.kind

D.

#observer.type and #vendor.name

What is the primary benefit of utilizing Next-Gen SIEM’s built-in dashboards?

A.

Direct access to raw log data

B.

Custom queries for specific events

C.

Quick insights without manual setup

D.

Capability to modify dashboard source code

Which three System alerts are enabled by default in Next-Gen SIEM for third-party connectors?

A.

Alert if connector receives no data in 24 hours

Alert if connector is disconnected

Resolve alerts within 30 days

B.

Alert if daily data ingestion limit exceeded

Alert if monthly data ingestion limit is exceeded

Resolve alerts within 30 days

C.

Alert if connector is disconnected

Alert if daily data ingestion limit exceeded

Alert if monthly data ingestion limit is exceeded

D.

Alert if connector receives no data in 24 hours

Alert if daily data ingestion limit exceeded

Alert if monthly data ingestion limit is exceeded

Which combination of scope and permissions must be configured to create an API token that allows you to create and get the results of a query job in Next-Gen SIEM?

A.

NGSIEM with both write and execute permissions

B.

NGSIEM with read permissions only

C.

NGSIEM with both read and write permissions

D.

NGSIEM with write permissions only

When setting up a data connector, which parser can be used to transform incoming data into searchable events that trigger detections in Next-Gen SIEM?

A.

CrowdStrike Parsing Standard (CPS) compliant parser

B.

Charlotte AI-generated parser

C.

VMWare ESXI parser

D.

Linux syslog parser

When creating an API client for Falcon SIEM Connector, which permission is required for the connector to read Falcon event streams?

A.

Hosts: Read

B.

Event Streams: Read

C.

Detection Management: Write

D.

Incidents: Read

An internal security team identified a small number of high-risk users. They ask you to create an app that will monitor these users and trigger an alert when specific suspicious behavior is detected.

Which Falcon feature should you use to develop this app?

A.

Falcon QueryBuilder

B.

Falcon Spotlight

C.

Falcon Foundry

D.

Charlotte AI

In the Next-Gen SIEM Connector Dashboard, what is the maximum retention period for which you can query third-party data ingestion metrics?

A.

30 days

B.

60 days

C.

90 days

D.

180 days