
Pass Your CrowdStrike Certified Falcon Administrator CCFA-200 Exam Easily with Accurate PDF Questions [Mar 02, 2023]
CCFA-200 Certification Exam Dumps Questions in here
CrowdStrike CCFA-200 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
NEW QUESTION 16
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?
- A. File exclusions are not aligned to groups or hosts
- B. There is no limit and exclusions can be applied to any or all groups
- C. There is a limit of three groups of hosts applied to any exclusion
- D. Each exclusion can be aligned to only one group of hosts
Answer: C
NEW QUESTION 17
How do you assign a Prevention policy to one or more hosts?
- A. Ensure the hosts are in a group and assign that group to a custom Prevention policy
- B. Modify the users roles on the User Management page
- C. Create a new policy and assign it directly to those hosts on the Host Management page
- D. Create a new policy and assign it directly to those hosts on the Prevention policy page
Answer: A
NEW QUESTION 18
How do you find a list of inactive sensors?
- A. Run the Inactive Sensor Report in the Host setup and management option
- B. A sensor is always considered active until removed by an Administrator
- C. Run the Sensor Aging Report within the Investigate option
- D. The Falcon platform does not provide reporting for inactive sensors
Answer: C
NEW QUESTION 19
Which of the following best describes the Default Sensor Update policy?
- A. The Default Sensor Update policy is a "catch-all" policy
- B. The Default Sensor Update policy is only used for testing sensor updates
- C. The Default Sensor Update policy is disabled by default
- D. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature
Answer: A
NEW QUESTION 20
In order to quarantine files on the host, what prevention policy settings must be enabled?
- A. Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be enabled
- B. Malware Protection and Custom Execution Blocking must be enabled
- C. Behavior-Based Threat Prevention sliders and Advanced Remediation Actions must be enabled
- D. Malware Protection and Windows Anti-Malware Execution Blocking must be enabled
Answer: D
NEW QUESTION 21
How do you assign a policy to a specific group of hosts?
- A. Assign a tag to the desired hosts in Host Management. Create a group with an assignment rule based on that tag. Go to the Assignment tab of the desired policy and click "Add Groups to Policy." Select the desired Group(s).
- B. Create a group containing the desired hosts using "Static Assignment." Go to the Assigned Host Groups tab of the desired policy and dick "Add groups to policy." Select the desired Group(s).
- C. On the Assignment tab of the desired policy, select "Static" assignment. From the next window, select the desired hosts (using fitters if needed) and click Add.
- D. Create a group containing the desired hosts using "Dynamic Assignment." Go to the Assigned Host Groups tab of the desired policy and select criteria such as OU, OS, Hostname pattern, etc.
Answer: D
NEW QUESTION 22
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
- A. Prevention Policy Debug
- B. Prevention Hashes Ignored
- C. Prevention Policy Audit Trail
- D. Machine-Learning Prevention Monitoring
Answer: C
NEW QUESTION 23
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
- A. Sensor version updates off
- B. Auto - TEST-QA
- C. Auto - N-1
- D. Specific sensor version number
Answer: D
NEW QUESTION 24
What is the purpose of precedence with respect to the Sensor Update policy?
- A. Precedence ensures that conflicting policy settings are not set in the same policy
- B. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
- C. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
- D. Precedence applies to the Prevention policy and not to the Sensor Update policy
Answer: C
NEW QUESTION 25
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A. The network protocols are different for each host OS
- B. It is an auditing requirement
- C. There may be special considerations for each OS
- D. To assist with testing and tracking sensor rollouts
Answer: B
NEW QUESTION 26
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
- A. Some network configurations, such as deep packet inspection, interfere with certificate validation
- B. Common sources of interference with certificate pinning include protocol race conditions and resource contention
- C. HTTPS interception should be enabled to proceed with certificate validation
- D. SSL inspection should be configured to occur on all Falcon traffic
Answer: A
NEW QUESTION 27
With Custom Alerts, it is possible to __________.
- A. schedule the alert to run at any interval
- B. receive an alert in an email
- C. be alerted to activity in real-time
- D. configure prevention actions for alerting
Answer: C
NEW QUESTION 28
Which of the following can a Falcon Administrator edit in an existing user's profile?
- A. Phone number
- B. Email address
- C. Working groups
- D. First or Last name
Answer: C
NEW QUESTION 29
Which option allows you to exclude behavioral detections from the detections page?
- A. Sensor Visibility Exclusion
- B. Machine Learning Exclusion
- C. IOA Exclusion
- D. IOC Exclusion
Answer: B
NEW QUESTION 30
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
- A. Agent ID (AID)
- B. Computer ID (CID)
- C. Endpoint ID (EID)
- D. Security ID (SID)
Answer: A
NEW QUESTION 31
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?
- A. TCP port 22 (SSH)
- B. TCP port 80 (HTTP)
- C. TCP port 443 (HTTPS)
- D. TCP UDP port 53 (DNS)
Answer: C
NEW QUESTION 32
What information is provided in Logan Activities under Visibility Reports?
- A. A list of unique users who are remotely logged on to devices based on the country
- B. A list of users who are remotely logged on to devices based on local IP and local port
- C. A list of all logons for all users
- D. A list of last endpoints that a user logged in to
Answer: D
NEW QUESTION 33
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?
- A. Real Time Responder - Administrator
- B. Real Time Responder - Script Developer
- C. Real Time Responder - Read Only Analyst
- D. Real Time Responder - Active Responder
Answer: B
NEW QUESTION 34
......
Verified CCFA-200 dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump: https://drive.google.com/open?id=1kZMrBqEkwHJqvNZ8tf4AwMydtnw5bIvK
Updated CCFA-200 Exam Practice Test Questions: https://www.prepawaypdf.com/CrowdStrike/CCFA-200-practice-exam-dumps.html