
Latest [Feb 27, 2024] CrowdStrike CCFA-200 Exam Practice Test To Gain Brilliante Result
Take a Leap Forward in Your Career by Earning CrowdStrike CCFA-200
The CCFA-200 certification exam is designed for administrators who are responsible for deploying, configuring, and managing the Falcon platform within their organizations. CCFA-200 exam is intended to validate the skills and knowledge of administrators who are able to leverage the full capabilities of the Falcon platform to protect their organizations from advanced threats.
NEW QUESTION # 73
How many days will an inactive host remain visible within the Host Management or Trash pages?
- A. 45 days
- B. 15 days
- C. 120 days
- D. 90 days
Answer: D
Explanation:
Explanation
An inactive host will remain visible within the Host Management or Trash pages for 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform. You can restore an inactive host from the Trash page if it becomes active again within 90 days1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 74
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A. There may be special considerations for each OS
- B. To assist with testing and tracking sensor rollouts
- C. The network protocols are different for each host OS
- D. It is an auditing requirement
Answer: A
Explanation:
Explanation
https://www.crowdstrike.com/blog/tech-center/how-to-manage-policies-in-falcon/
NEW QUESTION # 75
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
- A. Falcon UI Audit Trail
- B. Machine Learning Debug
- C. Sensor Report
- D. Machine Learning Prevention Monitoring
Answer: D
NEW QUESTION # 76
Custom IOA rules are defined using which syntax?
- A. PowerShell
- B. Regex
- C. Yara
- D. Glob
Answer: B
Explanation:
Explanation
Regex guidelines https://falcon.crowdstrike.com/documentation/68/detection-and-prevention-policies#regex
NEW QUESTION # 77
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
- A. Contact support and request that they modify the Machine Learning settings to no longer include this detection
- B. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
- C. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
- D. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
Answer: B
NEW QUESTION # 78
On which page of the Falcon console would you create sensor groups?
- A. Host management
- B. Sensor update policies
- C. User management
- D. Host groups
Answer: D
Explanation:
Explanation
The only place where create host groups is in " Host and setup management > host Groups> Create a group" In Sensor Update policies you can only asign a group of host to the policy not creating a group of hosts.
NEW QUESTION # 79
With Custom Alerts, it is possible to __________.
- A. schedule the alert to run at any interval
- B. configure prevention actions for alerting
- C. receive an alert in an email
- D. be alerted to activity in real-time
Answer: C
Explanation:
Explanation
The reporting interval is predefined and cannot be changed. You can only enable/disable the custom alert feature and add/remove recipient email client for the alert/detection.
NEW QUESTION # 80
How do you assign a policy to a specific group of hosts?
- A. Create a group containing the desired hosts using "Dynamic Assignment." Go to the Assigned Host Groups tab of the desired policy and select criteria such as OU, OS, Hostname pattern, etc.
- B. On the Assignment tab of the desired policy, select "Static" assignment. From the next window, select the desired hosts (using fitters if needed) and click Add.
- C. Create a group containing the desired hosts using "Static Assignment." Go to the Assigned Host Groups tab of the desired policy and dick "Add groups to policy." Select the desired Group(s).
- D. Assign a tag to the desired hosts in Host Management. Create a group with an assignment rule based on that tag. Go to the Assignment tab of the desired policy and click "Add Groups to Policy." Select the desired Group(s).
Answer: C
Explanation:
Explanation
The administrator can assign a policy to a specific group of hosts by creating a group containing the desired hosts using "Static Assignment." Then, go to the Assigned Host Groups tab of the desired policy and click
"Add groups to policy." Select the desired Group(s). This will apply the policy to the selected group(s) of hosts. The other options are either incorrect or not applicable to static assignment. Reference: [CrowdStrike Falcon User Guide], page 33.
NEW QUESTION # 81
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
- A. Add the CISO's email to the existing action
- B. Add a parallel action to send a custom email to your CISO
- C. Add a sequential action to send a custom email to your CISO
- D. Clone the workflow and replace the existing email with your CISO's email
Answer: C
NEW QUESTION # 82
Why is it important to know your company's event data retention limits in the Falcon platform?
- A. This is not necessary; you simply select "All Time" in your query to search all data
- B. You will not be able to search event data into the past beyond your retention period
- C. Data such as process records are kept for a shorter time than event data
- D. Your query will require you to specify the data pool associated with the date you wish to search
Answer: B
Explanation:
Explanation
It is important to know your company's event data retention limits in the Falcon platform because you will not be able to search event data into the past beyond your retention period. The retention period is the amount of time that event data is stored in the Falcon Cloud, and it may vary depending on your subscription plan and settings. The other options are either incorrect or not related to knowing your retention limits.
Reference: CrowdStrike Falcon User Guide, page 48.
NEW QUESTION # 83
Which role allows a user to connect to hosts using Real-Time Response?
- A. Prevention Hashes Manager
- B. Endpoint Manager
- C. Falcon Administrator
- D. Real Time Responder - Active Responder
Answer: D
NEW QUESTION # 84
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
Explanation
There are three "Auto" sensor version update options available for Windows Sensor Update Policies: Auto - N-1, Auto - TEST-QA and Auto - Latest. These options allow the administrator to automatically update the sensor version to the previous stable version, the latest test version or the latest stable version, respectively.
Reference: [CrowdStrike Falcon User Guide], page 38.
NEW QUESTION # 85
On the Host management page which filter could be used to quickly identify all devices categorized as a
"Workstation" by the Falcon Platform?
- A. Type
- B. Platform
- C. Hostname
- D. Status
Answer: A
Explanation:
Explanation
The filter that could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform on the Host Management page is Type. The Type filter allows you to filter hosts by their device type, such as workstation, server, or domain controller. The device type is assigned to each host based on their Active Directory domain structure. You can use the Type filter to quickly identify all hosts that have the workstation type assigned in their domain2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 86
Under which scenario can Sensor Tags be assigned?
- A. While installing a sensor
- B. While triaging a detection
- C. While updating a sensor in the Falcon console
- D. While managing hosts in the Falcon console
Answer: D
NEW QUESTION # 87
Why is the ability to disable detections helpful?
- A. It gives users the ability to set up hosts to test detections and later remove them from the console
- B. It gives users the ability to remove all data from hosts that have been uninstalled
- C. It gives users the ability to allowlist a false positive detection
- D. It gives users the ability to uninstall the sensor from a host
Answer: C
NEW QUESTION # 88
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
- A. From a command line, run the sc query csagent -version command
- B. Use the Sensor Report to filter to the specific endpoint
- C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details
- D. Use the Investigate > Host Search to filter to the specific endpoint
Answer: A
Explanation:
Explanation
From a command line, running the sc query csagent -version command is not a way to determine the sensor version installed on a specific endpoint. This command will only show the status of the csagent service, not the sensor version. The other options are valid ways to determine the sensor version installed on a specific endpoint using Falcon UI or API. You can use the Sensor Report, the Host Search, or the Host Management features to filter, search, or select the desired endpoint and view the sensor version information12.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike 2: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 89
What is the purpose of precedence with respect to the Sensor Update policy?
- A. Precedence ensures that conflicting policy settings are not set in the same policy
- B. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
- C. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
- D. Precedence applies to the Prevention policy and not to the Sensor Update policy
Answer: B
NEW QUESTION # 90
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
- A. *\Program Files\My Program\*\
- B. \Program Files\My Program\*
- C. \Program Files\My Program\My Files\*
- D. *\*
Answer: C
NEW QUESTION # 91
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
- A. Firewall Rule Group
- B. USB Device Policy
- C. Machine Learning Exclusions
- D. Containment Policy
Answer: C
Explanation:
Explanation
Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment.
The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested folder with a GLOB expression.
NEW QUESTION # 92
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
- A. HTTPS interception should be enabled to proceed with certificate validation
- B. Some network configurations, such as deep packet inspection, interfere with certificate validation
- C. SSL inspection should be configured to occur on all Falcon traffic
- D. Common sources of interference with certificate pinning include protocol race conditions and resource contention
Answer: B
Explanation:
Explanation
The statement that some network configurations, such as deep packet inspection, interfere with certificate validation is true concerning Falcon sensor certificate validation. The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks, which means that it verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. Some network configurations, such as deep packet inspection, SSL inspection, or HTTPS interception, may attempt to modify or replace the server certificate, which will cause the sensor to reject the connection and generate an error3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 93
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
- A. Engine (Full Visibility)
- B. Interpreter-Only
- C. Script-based Execution Monitoring
- D. Additional User Mode Data
Answer: C
Explanation:
Explanation
Turn on the Script-Based Execution Monitoring prevention policy setting to enable the "Falcon sensor to monitor the contents of scripts and shells that are popular mechanisms for executing malicious code on hosts.
This setting does not kill or block scripts."
Scripting languages:
Excel 4.0 macros
JScript
VBA Macros
VBScript
The Sensor Visibility setting that should be turned on within the Prevention policy settings to monitor suspicious VBA macros is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. VBA (Visual Basic for Applications) is a scripting language that can be embedded in Microsoft Office documents, such as Word or Excel. VBA macros can be used to automate tasks or perform actions within the documents, but they can also be abused by attackers to deliver malware or execute malicious code. Script-based Execution Monitoring can help detect and prevent such attacks by monitoring the contents of VBA macros for execution of malicious content.
References: : [Falcon Administrator Learning Path | Infographic | CrowdStrike]
NEW QUESTION # 94
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
- A. Only Mac
- B. Windows
- C. *nix
- D. Both Windows and *nix
Answer: A
Explanation:
Explanation
A Sensor Update Policy for the Mac platform will only manage Mac operating systems. Sensor Update Policies are platform-specific, meaning that they only apply to hosts that have the same operating system as the policy. For example, a Sensor Update Policy for Windows will only manage Windows hosts, and a Sensor Update Policy for Linux will only manage Linux hosts. You cannot create a Sensor Update Policy that manages multiple operating systems at once2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 95
What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?
- A. A Sensor Visibility exclusion
- B. A Custom IOC entry
- C. An IOA exclusion
- D. A Machine Learning exclusion
Answer: B
Explanation:
Explanation
The most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally is to create a Custom IOC entry. A Custom IOC (indicator of compromise) entry allows you to define custom rules for detecting or preventing malicious activity based on file hashes, file paths, IP addresses, or domains. You can use regex (regular expression) syntax to create a Custom IOC entry that matches the folder path that you want to block from being uploaded to the cloud1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 96
When troubleshooting the Falcon Sensor on Windows, what is the correct parameter to output the log directory to a specified file?
- A. /log log.txt
- B. LOG=log.txt
- C. \log log.txt
- D. C:\CSSensorlnstall\LogFiles
Answer: A
Explanation:
Explanation
The correct parameter to output the log directory to a specified file when troubleshooting the Falcon Sensor on Windows is /log log.txt. This parameter will create a log file named log.txt in the same folder where you run the sensor installation command. The log file will contain information about the sensor installation process, such as the parameters used, the actions performed, and any errors encountered3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 97
......
Authentic Best resources for CCFA-200 Online Practice Exam: https://exampdf.dumpsactual.com/CCFA-200-actualtests-dumps.html
