
PASS CCFA-200 exam with CrowdStrike Real Exam Questions - 100% Valid!
Actual CCFA-200 Exam Recently Updated Questions with Free Demo
CrowdStrike CCFA-200 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
NEW QUESTION 42
On a Windows host, what is the best command to determine if the sensor is currently running?
- A. sc query csagent
- B. netstat -a
- C. ping falcon.crowdstrike.com
- D. This cannot be accomplished with a command
Answer: A
NEW QUESTION 43
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?
- A. Bulk update key
- B. Customer ID (CID)
- C. Maintenance token
- D. Agent ID (AID)
Answer: C
NEW QUESTION 44
Which of the following can a Falcon Administrator edit in an existing user's profile?
- A. Phone number
- B. First or Last name
- C. Working groups
- D. Email address
Answer: C
NEW QUESTION 45
What is the purpose of precedence with respect to the Sensor Update policy?
- A. Precedence ensures that conflicting policy settings are not set in the same policy
- B. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
- C. Precedence applies to the Prevention policy and not to the Sensor Update policy
- D. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
Answer: D
NEW QUESTION 46
How do you disable all detections for a host?
- A. You cannot disable all detections on individual hosts as it would put them at risk
- B. Contact support and provide them with the Agent ID (AID) for the machine and they will put it on the Disabled Hosts list in your Customer ID (CID)
- C. Create an exclusion rule and apply it to the machine or group of machines
- D. In Host Management, select the host and then choose the option to Disable Detections
Answer: D
NEW QUESTION 47
Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?
- A. Real Time Responder
- B. Falcon Investigator
- C. Remediation Manager
- D. Endpoint Manager
Answer: B
NEW QUESTION 48
What impact does disabling detections on a host have on an API?
- A. Endpoints with detections disabled will not alert on anything until detections are enabled again
- B. Endpoints with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
- C. Endpoints cannot have their detections disabled individually
- D. DetectionSummaryEvent stops sending to the Streaming API for that host
Answer: B
NEW QUESTION 49
When creating new IOCs in IOC management, which of the following fields must be configured?
- A. Hash, Platform and Action
- B. Hash, Description, Filename
- C. Filename, Severity and Expiry Date
- D. Hash, Action and Expiry Date
Answer: A
NEW QUESTION 50
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
- A. Base URL
- B. Secret
- C. Client ID
- D. Client name
Answer: B
NEW QUESTION 51
The alignment of a particular prevention policy to one or more host groups can be completed in which of the following locations within Falcon?
- A. Policy alignment is configured only once during the initial creation of the policy in the "Create New Policy" pop-up window
- B. Policy alignment is configured in the "Host Management" section in the Hosts application
- C. Policy alignment is configured in the General Settings section under the Configuration menu
- D. Policy alignment is configured in each policy in the "Assigned Host Groups" tab
Answer: D
NEW QUESTION 52
The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.
- A. the logon type (e.g. interactive, service)
- B. all hosts the user logged into
- C. the last time the user's password was set
- D. the account type for the user (e.g. Domain Administrator, Local User)
Answer: C
NEW QUESTION 53
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
- A. A host was offline for more than 24 hours
- B. A host was placed in network containment from a detection
- C. A Sensor Update Policy was misconfigured
- D. A patch was pushed overnight to all Windows systems
Answer: D
NEW QUESTION 54
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
- A. Falcon UI Audit Trail
- B. Sensor Report
- C. Machine Learning Prevention Monitoring
- D. Machine Learning Debug
Answer: C
NEW QUESTION 55
When would the No Action option be assigned to a hash in IOC Management?
- A. When you want to save the indicator for later action, but do not want to block or allow it at this time
- B. Add the indicator to your blocklist and show it as a detection
- C. Add the indicator to your allowlist and do not detect it
- D. There is no such option as No Action available in the Falcon console
Answer: A
NEW QUESTION 56
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
- A. Under Host setup and management, choose the Disabled Sensors Report. Change the time range to 30 days
- B. Under Dashboards and reports, choose the Sensor Report. Set the "Last Seen" dropdown to 30 days and reference the Inactive Sensors widget
- C. Under Host setup and management, choose the Host Management page. Set the group filter to "Inactive Sensors"
- D. Under Host setup and management > Managed endpoints > Inactive Sensors. Change the time range to 30 days
Answer: D
NEW QUESTION 57
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
- A. Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"
- B. Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running
- C. Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"
- D. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.
Answer: D
NEW QUESTION 58
What is the goal of a Network Containment Policy?
- A. Limit the impact of a compromised host on the network
- B. Gain more visibility into network activities
- C. Increase the aggressiveness of the assigned prevention policy
- D. Partition a network for privacy
Answer: A
NEW QUESTION 59
What type of information is found in the Linux Sensors Dashboard?
- A. Hosts by Kernel Version, Shells spawned by Root, Wget/Curl Usage
- B. Versions running, Directory Made Invisible to Spotlight, Logging/Auditing Referenced, Viewed, or Modified
- C. Private Information Accessed, Archiving Tools - Exfil, Files Made Executable
- D. Hidden File execution, Execution of file from the trash, Versions Running with Computer Names
Answer: B
NEW QUESTION 60
......
CCFA-200 Free Sample Questions to Practice One Year Update: https://www.practicetorrent.com/CCFA-200-practice-exam-torrent.html
Free CrowdStrike CCFA-200 Exam Questions: https://drive.google.com/open?id=1DrUTi2QPSGZOuaBsgDFsBBY68mmZ8xgk