[Q16-Q34] Pass Your CrowdStrike Certified Falcon Administrator CCFA-200 Exam Easily with Accurate PDF Questions [Mar 02, 2023]

Share

Pass Your CrowdStrike Certified Falcon Administrator CCFA-200 Exam Easily with Accurate PDF Questions [Mar 02, 2023]

CCFA-200 Certification Exam Dumps Questions in here


CrowdStrike CCFA-200 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Resolve policy settings, permissions and threshold issues
  • Apply basic sensor install requirements and installation processes
Topic 2
  • Explain what information can be found in the visibility reports
  • Explain where build versions are visible for a single sensor or across your environment
Topic 3
  • Allowlist network traffic so it can connect to contained hosts
  • Explain the information shown in the remote logon activity report
Topic 4
  • Determine which reports to use when reporting on information relating to a host
  • Apply appropriate settings to successfully install a Falcon sensor on Windows, Linux and macOS
Topic 5
  • Explain what information is contained in Machine-Learning Prevention Monitoring Report
  • Explain the effect of disabling detections on a host
Topic 6
  • Explain what precedence does regarding prevention policies
  • Determine roles required for access to features and functionality in the Falcon console
Topic 7
  • Perform root cause analysis related to system
  • user issues
  • Apply additional
  • advanced options for images
  • VDIs, tokens and tags
Topic 8
  • Create a new user, delete a user and edit a user, etc
  • Describe the capabilities and limitations of each RTR role
Topic 9
  • Describe policy types, components, application and workflow
  • Propose how filtering might be used in the Host Management page
Topic 10
  • Explain the differences between the visibility and hunting reports
  • Explain what information is in the Falcon UI Audit Trail Report
Topic 11
  • Configure custom alerts to notify individuals about policies, detections and incidents
  • Recall how long inactive sensors are retained to define your data backup plan

 

NEW QUESTION 16
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?

  • A. File exclusions are not aligned to groups or hosts
  • B. There is no limit and exclusions can be applied to any or all groups
  • C. There is a limit of three groups of hosts applied to any exclusion
  • D. Each exclusion can be aligned to only one group of hosts

Answer: C

 

NEW QUESTION 17
How do you assign a Prevention policy to one or more hosts?

  • A. Ensure the hosts are in a group and assign that group to a custom Prevention policy
  • B. Modify the users roles on the User Management page
  • C. Create a new policy and assign it directly to those hosts on the Host Management page
  • D. Create a new policy and assign it directly to those hosts on the Prevention policy page

Answer: A

 

NEW QUESTION 18
How do you find a list of inactive sensors?

  • A. Run the Inactive Sensor Report in the Host setup and management option
  • B. A sensor is always considered active until removed by an Administrator
  • C. Run the Sensor Aging Report within the Investigate option
  • D. The Falcon platform does not provide reporting for inactive sensors

Answer: C

 

NEW QUESTION 19
Which of the following best describes the Default Sensor Update policy?

  • A. The Default Sensor Update policy is a "catch-all" policy
  • B. The Default Sensor Update policy is only used for testing sensor updates
  • C. The Default Sensor Update policy is disabled by default
  • D. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature

Answer: A

 

NEW QUESTION 20
In order to quarantine files on the host, what prevention policy settings must be enabled?

  • A. Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be enabled
  • B. Malware Protection and Custom Execution Blocking must be enabled
  • C. Behavior-Based Threat Prevention sliders and Advanced Remediation Actions must be enabled
  • D. Malware Protection and Windows Anti-Malware Execution Blocking must be enabled

Answer: D

 

NEW QUESTION 21
How do you assign a policy to a specific group of hosts?

  • A. Assign a tag to the desired hosts in Host Management. Create a group with an assignment rule based on that tag. Go to the Assignment tab of the desired policy and click "Add Groups to Policy." Select the desired Group(s).
  • B. Create a group containing the desired hosts using "Static Assignment." Go to the Assigned Host Groups tab of the desired policy and dick "Add groups to policy." Select the desired Group(s).
  • C. On the Assignment tab of the desired policy, select "Static" assignment. From the next window, select the desired hosts (using fitters if needed) and click Add.
  • D. Create a group containing the desired hosts using "Dynamic Assignment." Go to the Assigned Host Groups tab of the desired policy and select criteria such as OU, OS, Hostname pattern, etc.

Answer: D

 

NEW QUESTION 22
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?

  • A. Prevention Policy Debug
  • B. Prevention Hashes Ignored
  • C. Prevention Policy Audit Trail
  • D. Machine-Learning Prevention Monitoring

Answer: C

 

NEW QUESTION 23
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?

  • A. Sensor version updates off
  • B. Auto - TEST-QA
  • C. Auto - N-1
  • D. Specific sensor version number

Answer: D

 

NEW QUESTION 24
What is the purpose of precedence with respect to the Sensor Update policy?

  • A. Precedence ensures that conflicting policy settings are not set in the same policy
  • B. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
  • C. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
  • D. Precedence applies to the Prevention policy and not to the Sensor Update policy

Answer: C

 

NEW QUESTION 25
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?

  • A. The network protocols are different for each host OS
  • B. It is an auditing requirement
  • C. There may be special considerations for each OS
  • D. To assist with testing and tracking sensor rollouts

Answer: B

 

NEW QUESTION 26
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?

  • A. Some network configurations, such as deep packet inspection, interfere with certificate validation
  • B. Common sources of interference with certificate pinning include protocol race conditions and resource contention
  • C. HTTPS interception should be enabled to proceed with certificate validation
  • D. SSL inspection should be configured to occur on all Falcon traffic

Answer: A

 

NEW QUESTION 27
With Custom Alerts, it is possible to __________.

  • A. schedule the alert to run at any interval
  • B. receive an alert in an email
  • C. be alerted to activity in real-time
  • D. configure prevention actions for alerting

Answer: C

 

NEW QUESTION 28
Which of the following can a Falcon Administrator edit in an existing user's profile?

  • A. Phone number
  • B. Email address
  • C. Working groups
  • D. First or Last name

Answer: C

 

NEW QUESTION 29
Which option allows you to exclude behavioral detections from the detections page?

  • A. Sensor Visibility Exclusion
  • B. Machine Learning Exclusion
  • C. IOA Exclusion
  • D. IOC Exclusion

Answer: B

 

NEW QUESTION 30
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?

  • A. Agent ID (AID)
  • B. Computer ID (CID)
  • C. Endpoint ID (EID)
  • D. Security ID (SID)

Answer: A

 

NEW QUESTION 31
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?

  • A. TCP port 22 (SSH)
  • B. TCP port 80 (HTTP)
  • C. TCP port 443 (HTTPS)
  • D. TCP UDP port 53 (DNS)

Answer: C

 

NEW QUESTION 32
What information is provided in Logan Activities under Visibility Reports?

  • A. A list of unique users who are remotely logged on to devices based on the country
  • B. A list of users who are remotely logged on to devices based on local IP and local port
  • C. A list of all logons for all users
  • D. A list of last endpoints that a user logged in to

Answer: D

 

NEW QUESTION 33
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?

  • A. Real Time Responder - Administrator
  • B. Real Time Responder - Script Developer
  • C. Real Time Responder - Read Only Analyst
  • D. Real Time Responder - Active Responder

Answer: B

 

NEW QUESTION 34
......

Verified CCFA-200 dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump: https://drive.google.com/open?id=1kZMrBqEkwHJqvNZ8tf4AwMydtnw5bIvK

Updated CCFA-200 Exam Practice Test Questions: https://www.prepawaypdf.com/CrowdStrike/CCFA-200-practice-exam-dumps.html