Pass the CrowdStrike CrowdStrike Falcon Certification Program CCFA-200 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?

Options:

A.

Detection slider: Extra Aggressive

Prevention slider: Cautious


B.

Detection slider: Moderate

Prevention slider: Disabled


C.

Detection slider: Cautious

Prevention slider: Cautious


D.

Detection slider: Disabled

Prevention slider: Disabled


Expert Solution
Questions # 2:

Which of the following is NOT an available action for an API Client?

Options:

A.

Edit an API Client


B.

Reset an API Client Secret


C.

Retrieve an API Client Secret


D.

Delete an API Client


Expert Solution
Questions # 3:

Where in the Falcon console can information about supported operating system versions be found?

Options:

A.

Configuration module


B.

Intelligence module


C.

Support module


D.

Discover module


Expert Solution
Questions # 4:

Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?

Options:

A.

Use the Sensor Report to filter to the specific endpoint


B.

Use the Investigate > Host Search to filter to the specific endpoint


C.

Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details


D.

From a command line, run the sc query csagent -version command


Expert Solution
Questions # 5:

Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?

Options:

A.

Grant the Falcon Package Full Disk Access, install the Falcon package, use falconctl to license the sensor


B.

Install the Falcon package passing it the installation token in the command line


C.

Install the Falcon package, use falconctl to license the sensor, approve the system extension, grant the sensor Full Disk Access


D.

Grant the Falcon Package Full Disk Access, install the Falcon package, load the Falcon Sensor with the command 'falconctl stats'


Expert Solution
Questions # 6:

What is the purpose of using groups with Sensor Update policies in CrowdStrike Falcon?

Options:

A.

To group hosts with others in the same business unit


B.

To group hosts according to the order in which Falcon was installed, so that updates are installed in the same order every time


C.

To prioritize the order in which Falcon updates are installed, so that updates are not installed all at once leading to network congestion


D.

To allow the controlled assignment of sensor versions onto specific hosts


Expert Solution
Questions # 7:

Custom IOA rules are defined using which syntax?

Options:

A.

Glob


B.

PowerShell


C.

Yara


D.

Regex


Expert Solution
Questions # 8:

Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?

Options:

A.

Workflow Execution log


B.

Falcon Ul Audit Trail


C.

Workflow Audit log


D.

Custom Alert History


Expert Solution
Questions # 9:

Which of the following uses Regex to create a detection or take a preventative action?

Options:

A.

Custom IOC


B.

Machine Learning Exclusion


C.

Custom IOA


D.

Sensor Visibility Exclusion


Expert Solution
Questions # 10:

Under which scenario can Sensor Tags be assigned?

Options:

A.

While triaging a detection


B.

While managing hosts in the Falcon console


C.

While updating a sensor in the Falcon console


D.

While installing a sensor


Expert Solution
Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions