Pass the CrowdStrike CrowdStrike Falcon Certification Program CCFA-200 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?

Options:

A.

Script-based Execution Monitoring


B.

FileSystem Visibility


C.

Engine (Full Visibility)


D.

Suspicious Scripts and Commands


Expert Solution
Questions # 12:

When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?

Options:

A.

Base URL


B.

Secret


C.

Client ID


D.

Client name


Expert Solution
Questions # 13:

You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?

Options:

A.

System monitoring will be unavailable


B.

Event reporting will be unavailable


C.

Prevention patterns will not be triggered


D.

Some detection patterns and preventions will not be triggered


Expert Solution
Questions # 14:

What best describes the relationship between Sensor Update policies and Operating Systems?

Options:

A.

Windows and Mac share Sensor Update policies. Linux requires its own set of polices based on the different kernel versions


B.

Sensor Update polices are not Operating System specific. One policy can be applied to all Operating Systems


C.

Windows has its own Sensor Update polices. But Mac and Linux share Sensor Update policies


D.

A Sensor Update policy must be configured for each Operating System (Windows, Mac, Linux)


Expert Solution
Questions # 15:

What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?

Options:

A.

A Machine Learning exclusion


B.

A Sensor Visibility exclusion


C.

An IOA exclusion


D.

A Custom IOC entry


Expert Solution
Questions # 16:

Which statement is TRUE regarding disabling detections on a host?

Options:

A.

Hosts with detections disabled will not alert on blocklisted hashes or machine learning detections, but will still alert on lOA-based detections. It will remain that way until detections are enabled again


B.

Hosts with detections disabled will not alert on anything until detections are enabled again


C.

Hosts with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed


D.

Hosts cannot have their detections disabled individually


Expert Solution
Questions # 17:

The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?

Options:

A.

SSL inspection should be configured to occur on all Falcon traffic


B.

Some network configurations, such as deep packet inspection, interfere with certificate validation


C.

HTTPS interception should be enabled to proceed with certificate validation


D.

Common sources of interference with certificate pinning include protocol race conditions and resource contention


Expert Solution
Questions # 18:

On which page of the Falcon console can one locate the Customer ID (CID)?

Options:

A.

Hosts Management


B.

API Clients and Keys


C.

Sensor Dashboard


D.

Sensor Downloads


Expert Solution
Questions # 19:

You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?

Options:

A.

*nix


B.

Windows


C.

Both Windows and *nix


D.

Only Mac


Expert Solution
Questions # 20:

An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?

Options:

A.

Custom Alert History


B.

Workflow Execution log


C.

Workflow Audit log


D.

Falcon UI Audit Trail


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions