Pass the CrowdStrike CrowdStrike Falcon Certification Program CCFA-200 Questions and answers with CertsForce

Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions
Questions # 41:

Which statement describes what is recommended for the Default Sensor Update policy?

Options:

A.

The Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible


B.

The Default Sensor Update should be configured to always automatically upgrade to the latest sensor version


C.

Since the Default Sensor Update policy is pre-configured with recommend settings out of the box, configuration of the Default Sensor Update policy is not required


D.

No configuration is required. Once a Custom Sensor Update policy is created the Default Sensor Update policy is disabled


Expert Solution
Questions # 42:

When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?

Options:

A.

Custom IOA Rule Groups


B.

Custom IOC Groups


C.

Enterprise Groups


D.

Operating System Groups


Expert Solution
Questions # 43:

To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

Options:

A.

Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead


B.

Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only


C.

Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block


D.

Using IOC management, import the list of hashes and IP addresses and set the action to No Action


Expert Solution
Questions # 44:

One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?

Options:

A.

USB Device Policy


B.

Firewall Rule Group


C.

Containment Policy


D.

Machine Learning Exclusions


Expert Solution
Questions # 45:

What command should be run to verify if a Windows sensor is running?

Options:

A.

regedit myfile.reg


B.

sc query csagent


C.

netstat -f


D.

ps -ef | grep falcon


Expert Solution
Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions