Exit demo CCFA-200 CrowdStrike Certified Falcon Administrator PDF format · free preview

CrowdStrike CCFA-200 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/ccfa-200.html

Question 1
Single choice

How long are detection events kept in Falcon?

A.

Detection events are kept for 90 days

B.

Detections events are kept for your subscribed data retention period

C.

Detection events are kept for 7 days

D.

Detection events are kept for 30 days

Question 2
Single choice

Which of the following is NOT an available filter on the Hosts Management page?

A.

Hostname

B.

Username

C.

Group

D.

OS Version

Question 3
Single choice

Which of the following pages provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System?

A.

Support and resources

B.

Activity Overview

C.

Hosts Overview

D.

Sensor Health

Question 4
Single choice

You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints.

What is the best way to prevent these in the future?

A.

Contact support and request that they modify the Machine Learning settings to no longer include this detection

B.

Using IOC Management, add the hash of the binary in question and set the action to "Allow"

C.

Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"

D.

Using IOC Management, add the hash of the binary in question and set the action to "No Action"

Question 5
Single choice

Which role will allow someone to manage quarantine files?

A.

Falcon Security Lead

B.

Detections Exceptions Manager

C.

Falcon Analyst ?Read Only

D.

Endpoint Manager

Question 6
Single choice

What information is provided in Logan Activities under Visibility Reports?

A.

A list of all logons for all users

B.

A list of last endpoints that a user logged in to

C.

A list of users who are remotely logged on to devices based on local IP and local port

D.

A list of unique users who are remotely logged on to devices based on the country

Question 7
Single choice

What are custom alerts based on?

A.

Custom workflows

B.

Custom event based triggers

C.

Predefined alert templates

D.

User defined Splunk queries

Question 8
Single choice

How can a API client secret be viewed after it has been created?

A.

Within the API management page, API client secrets can be accessed within the "edit client" functionality

B.

The API client secret must be reset or a new client created as the secret cannot be viewed after it has been created

C.

The API client secret can be provided by support via direct email request from a Falcon Administrator

D.

Selecting "show secret" within the 3-dot dropdown menu will reveal the secret for the selected api client

Question 9
Single choice

Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host.

What is the most appropriate role that can be added to fullfil this requirement?

A.

Remediation Manager

B.

Real Time Responder ?Read Only Analyst

C.

Falcon Analyst ?Read Only

D.

Real Time Responder ?Active Responder

Question 10
Single choice

When a host is placed in Network Containment, which of the following is TRUE?

A.

The host machine is unable to send or receive network traffic outside of the local network

B.

The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and traffic allowed in the Firewall Policy

C.

The host machine is unable to send or receive any network traffic

D.

The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and any resources allowlisted in the Containment Policy

Showing 10 of 186 questions · Unlock the full set