
Latest [Mar 09, 2023] CCFA-200 Exam Dumps - Valid and Updated Dumps
Free Sales Ending Soon - 100% Valid CCFA-200 Exam Dumps with 99 Questions
CrowdStrike CCFA-200 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
NEW QUESTION 53
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
- A. Base URL
- B. Secret
- C. Client ID
- D. Client name
Answer: B
NEW QUESTION 54
Which of the following is a valid step when troubleshooting sensor installation failure?
- A. Enable the Windows firewall
- B. Delete any available application crash log files
- C. Disable SSL and TLS on the host
- D. Confirm all required services are running on the system
Answer: D
NEW QUESTION 55
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
- A. Custom Alert History
- B. Workflow Execution log
- C. Falcon UI Audit Trail
- D. Workflow Audit log
Answer: B
NEW QUESTION 56
With Custom Alerts, it is possible to __________.
- A. configure prevention actions for alerting
- B. schedule the alert to run at any interval
- C. be alerted to activity in real-time
- D. receive an alert in an email
Answer: C
NEW QUESTION 57
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
- A. Under Dashboards and reports, choose the Sensor Report. Set the "Last Seen" dropdown to 30 days and reference the Inactive Sensors widget
- B. Under Host setup and management > Managed endpoints > Inactive Sensors. Change the time range to 30 days
- C. Under Host setup and management, choose the Host Management page. Set the group filter to "Inactive Sensors"
- D. Under Host setup and management, choose the Disabled Sensors Report. Change the time range to 30 days
Answer: B
NEW QUESTION 58
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 59
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
- A. Auto - TEST-QA
- B. Sensor version updates off
- C. Auto - N-1
- D. Specific sensor version number
Answer: D
NEW QUESTION 60
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
- A. Both Windows and *nix
- B. Only Mac
- C. Windows
- D. *nix
Answer: A
NEW QUESTION 61
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
- A. Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"
- B. Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running
- C. Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"
- D. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.
Answer: D
NEW QUESTION 62
How do you disable all detections for a host?
- A. Create an exclusion rule and apply it to the machine or group of machines
- B. Contact support and provide them with the Agent ID (AID) for the machine and they will put it on the Disabled Hosts list in your Customer ID (CID)
- C. You cannot disable all detections on individual hosts as it would put them at risk
- D. In Host Management, select the host and then choose the option to Disable Detections
Answer: D
NEW QUESTION 63
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?
- A. Go to Host Management in the Host page. Select the host and use the Export Detections button
- B. In the Investigate module, access the Detection Activity page. Use the filters to focus on the appropriate hostname and time, then export the results
- C. Utilize the Detection Resolution Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detection Resolution History" section
- D. Utilize the Detection Activity Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detections by Host" section
Answer: B
NEW QUESTION 64
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
- A. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
- B. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
- C. Contact support and request that they modify the Machine Learning settings to no longer include this detection
- D. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
Answer: A
NEW QUESTION 65
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
- A. Detection slider: Extra Aggressive
Prevention slider: Cautious - B. Detection slider: Moderate
Prevention slider: Disabled - C. Detection slider: Cautious
Prevention slider: Cautious - D. Detection slider: Disabled
Prevention slider: Disabled
Answer: C
NEW QUESTION 66
What information is provided in Logan Activities under Visibility Reports?
- A. A list of users who are remotely logged on to devices based on local IP and local port
- B. A list of unique users who are remotely logged on to devices based on the country
- C. A list of all logons for all users
- D. A list of last endpoints that a user logged in to
Answer: D
NEW QUESTION 67
Under the "Next-Gen Antivirus: Cloud Machine Learning" setting there are two categories, one of them is "Cloud Anti-Malware" and the other is:
- A. Advanced Machine Learning
- B. Adware & PUP
- C. Sensor Anti-Malware
- D. Execution Blocking
Answer: A
NEW QUESTION 68
Why is the ability to disable detections helpful?
- A. It gives users the ability to uninstall the sensor from a host
- B. It gives users the ability to remove all data from hosts that have been uninstalled
- C. It gives users the ability to allowlist a false positive detection
- D. It gives users the ability to set up hosts to test detections and later remove them from the console
Answer: C
NEW QUESTION 69
What are custom alerts based on?
- A. Custom workflows
- B. Custom event based triggers
- C. User defined Splunk queries
- D. Predefined alert templates
Answer: B
NEW QUESTION 70
When a host is placed in Network Containment, which of the following is TRUE?
- A. The host machine is unable to send or receive any network traffic
- B. The host machine is unable to send or receive network traffic outside of the local network
- C. The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and traffic allowed in the Firewall Policy
- D. The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and any resources allowlisted in the Containment Policy
Answer: D
NEW QUESTION 71
......
CCFA-200 Exam Dumps - 100% Marks In CCFA-200 Exam: https://pass4sure.exam-killer.com/CCFA-200-valid-questions.html

