Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the CrowdStrike CrowdStrike CCSE CCSE-204 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What dashboard presents a view of third-party data ingestion over the past 30 days?

Options:

A.

Sensor Usage Dashboard


B.

Sensor Subscription Dashboard


C.

Falcon Flex Dashboard


D.

Next-Gen SIEM Connector Dashboard


Expert Solution
Questions # 2:

What is the purpose of labels in Fleet Management?

Options:

A.

Set passwords for collector instances


B.

Categorize collectors for group configurations


C.

Monitor network traffic


D.

Assign IP addresses to collectors


Expert Solution
Questions # 3:

You need to ingest data from a custom internal application hosted on-prem. The application writes logs to a file on a syslog server.

Which data connector would you use?

Options:

A.

Google Cloud Pub / Sub Data Connector


B.

HTTP Event Connector


C.

Amazon S3 Data Connector


D.

Azure Virtual Machines Data Connector


Expert Solution
Questions # 4:

You suspect that an API key you recently generated has been compromised.

What should you do?

Options:

A.

Regenerate a new API key directly from the platform


B.

Search the audit logs for the connector creation event and replicate it


C.

View the API key details in the platform and clone a new API key


D.

Contact CrowdStrike Support to retrieve and send the key to you


Expert Solution
Questions # 5:

What are the four required CPS-compliant Event parser tags?

Options:

A.

event.category

event.kind

event.module

event.outcome


B.

event.category

event.dataset

event.kind

event.outcome


C.

event.dataset

event.kind

event.module

event.outcome


Expert Solution
Questions # 6:

You want a consistent view of events from various data sources.

Which ECS field type should you normalize?

Options:

A.

Base Fields


B.

Extended Fields


C.

Detection Fields


D.

Core Fields


Expert Solution
Questions # 7:

Which field should be used in a correlation rule when detections must be based on the original event occurrence time?

Options:

A.

@ingesttimestamp


B.

@timestamp


C.

@rawstring


D.

@id


Expert Solution
Questions # 8:

What is the most appropriate action if a third-party connector is disconnected and no longer ingesting data?

Options:

A.

Delete the related parser immediately


B.

Ignore it until the monthly ingestion report updates


C.

Review connector health and reconnect or reauthorize the integration


D.

Change all searches to Falcon-only data


Expert Solution
Questions # 9:

Which are valid parse functions in CQL?

Options:

A.

parseCEF()

parseIETF()

parseJson()


B.

parseCEF()

parseJson()

parseXml()


C.

parseCEF()

parseIETF()

parseXml()


D.

parseIETF()

parseJson()

parseXml(


Expert Solution
Questions # 10:

A Falcon Log Collector has been configured with 4 sinks of type memory, each having a queue size of 2GB.

What is the minimum memory requirement produced by this configuration?

Options:

A.

9 GB


B.

12 GB


C.

10 GB


D.

8 GB


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions