Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the CrowdStrike CrowdStrike CCSE CCSE-204 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which combination of scope and permissions must be configured to create an API token that allows you to create and get the results of a query job in Next-Gen SIEM?

Options:

A.

NGSIEM with both write and execute permissions


B.

NGSIEM with read permissions only


C.

NGSIEM with both read and write permissions


D.

NGSIEM with write permissions only


Expert Solution
Questions # 12:

Which role is most appropriate when a user only needs to view SIEM investigations and dashboards but must not modify content?

Options:

A.

NG SIEM Administrator


B.

NG SIEM Security Lead


C.

NG SIEM Analyst


D.

NG SIEM Analyst – Read Only


Expert Solution
Questions # 13:

You are reviewing logs and find that the content appears as one large block of text within the @rawstring field for incoming firewall logs. The other expected structured fields are empty.

What is the cause of this issue?

Options:

A.

The parser was incorrect


B.

The ingestion token is invalid


C.

The sink was overloaded


D.

The timestamp format is incorrect


Expert Solution
Questions # 14:

You are performing a search query using data from the Falcon Sensor and third-party data connectors.

Which Advanced Event Search data source should you choose?

Options:

A.

All


B.

Falcon


C.

Third-party


D.

Custom


Expert Solution
Questions # 15:

Which CQL statement below includes correct placement of the AND statements and the pipe symbol?

Options:

A.

#sourcefile="jobfilename" AND stdout=/\[[\+]\] / | groupBy([hostname], function=collect([hostname,stdout] )) AND stdout != "" AND stdout != "* No artifacts *" | select([hostname,stdout])


B.

#sourcefile="jobfilename" | stdout=/\[[\+]\] / | groupBy([hostname], function=collect([hostname,stdout] )) | stdout != "" AND stdout != "* No artifacts *" AND select([hostname,stdout])


C.

#sourcefile="jobfilename" AND stdout=/\[[\+]\] / | groupBy([hostname], function=collect([hostname,stdout] )) | stdout != "" AND stdout != "* No artifacts *" | select([hostname,stdout])


D.

#sourcefile="jobfilename" | stdout=/\[[\+]\] / AND groupBy([hostname], function=collect([hostname,stdout] )) AND stdout ! = "" | stdout != "* No artifacts *" | select([hostname,stdout])


Expert Solution
Questions # 16:

In the Next-Gen SIEM Connector Dashboard, what is the maximum retention period for which you can query third-party data ingestion metrics?

Options:

A.

30 days


B.

60 days


C.

90 days


D.

180 days


Expert Solution
Questions # 17:

What is the recommended order of the three required activities to build an efficient CQL query?

Options:

A.

Filter > Format > Aggregate


B.

Filter > Aggregate > Format


C.

Format > Filter > Aggregate


D.

Aggregate > Filter > Format


Expert Solution
Questions # 18:

You need to provide a colleague the appropriate role to allow for configuration of connectors and creation of SOAR automations in Next-Gen SIEM.

Which role will provide these permissions while also maintaining least privilege?

Options:

A.

NG SIEM Security Lead


B.

NG SIEM Analyst


C.

Falcon Security Lead


D.

Custom role


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions