Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CrowdStrike CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?

Options:

A.

Customer ID and Integration ID


B.

Client ID and Secret


C.

Customer ID and Secret


D.

Client ID and OAuth2 ID


Expert Solution
Questions # 2:

You have 100 hashes that have been prohibited by management and need to be blocked within your organization. Using Falcon, what is the best way to accomplish this?

Options:

A.

Navigate to Configure > IOC Management. Add a custom IOC. Add the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.


B.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block. Verify Custom Execution Blocking is active.


C.

Navigate to Configure > IOC Management. Add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.


D.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block and Alert. Verify Custom Blocking inside Execution Blocking is active.


Expert Solution
Questions # 3:

An inactive host does not contact the Falcon cloud. What is the default number of days after which it is automatically removed from the Host Management page?

Options:

A.

30 Days


B.

90 Days


C.

45 Days


Expert Solution
Questions # 4:

A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools


B.

Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools


C.

Remove Host containment and update the host with all patches


D.

Create a Firewall Policy that allow lists your patch management tools


Expert Solution
Questions # 5:

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

Options:

A.

All detection data for the host is deleted and the host is hidden from view


B.

Existing detections for the host remain


C.

New detections are disabled for 30 days


D.

The detections for the host are removed from the console immediately


Expert Solution
Questions # 6:

After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?

Options:

A.

Falcon requires a 24-hour waiting period to apply custom policies to newly installed hosts


B.

A host-based firewall rule is preventing the custom policy from applying successfully


C.

The laptop is not a member of a host group assigned to the custom policy


D.

A prompt to apply the new prevention policy was manually declined


Expert Solution
Questions # 7:

What prevention policy settings must be enabled to quarantine files on the host?

Options:

A.

Quarantine Files; Windows Anti-Malware Execution Blocking


B.

Malware Protection; Custom Execution Blocking


C.

Next-Gen Antivirus Prevention sliders; Quarantine & Security Center Registration


D.

Advanced Remediation Actions; Quarantine level set to Aggressive


Expert Solution
Questions # 8:

A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the FQDN of your patch management tools


B.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools


C.

Adjust the Content Update Policies to Early Access with No Delay


D.

Create an IP group in IP Allowlist Management


Expert Solution
Questions # 9:

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

Options:

A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled


B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console


C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console


D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon


Expert Solution
Questions # 10:

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

Options:

A.

Delete the detections in the console and contain the server undergoing the test


B.

Temporarily disable detections for the server in Host Management and reenable after the test is done


C.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection


D.

Permanently disable detections for the server in Host Management


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions