
Try CCFA-200 Exam Valid Dumps with Instant Download Free Updates
CCFA-200 Dumps First Attempt Guaranteed Success
NEW QUESTION # 51
With Custom Alerts, it is possible to __________.
- A. configure prevention actions for alerting
- B. be alerted to activity in real-time
- C. receive an alert in an email
- D. schedule the alert to run at any interval
Answer: C
Explanation:
Explanation
The reporting interval is predefined and cannot be changed. You can only enable/disable the custom alert feature and add/remove recipient email client for the alert/detection.
NEW QUESTION # 52
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
- A. SSL inspection should be configured to occur on all Falcon traffic
- B. Some network configurations, such as deep packet inspection, interfere with certificate validation
- C. Common sources of interference with certificate pinning include protocol race conditions and resource contention
- D. HTTPS interception should be enabled to proceed with certificate validation
Answer: B
Explanation:
Explanation
The statement that some network configurations, such as deep packet inspection, interfere with certificate validation is true concerning Falcon sensor certificate validation. The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks, which means that it verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. Some network configurations, such as deep packet inspection, SSL inspection, or HTTPS interception, may attempt to modify or replace the server certificate, which will cause the sensor to reject the connection and generate an error3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 53
When would the No Action option be assigned to a hash in IOC Management?
- A. Add the indicator to your blocklist and show it as a detection
- B. When you want to save the indicator for later action, but do not want to block or allow it at this time
- C. There is no such option as No Action available in the Falcon console
- D. Add the indicator to your allowlist and do not detect it
Answer: B
Explanation:
Explanation
The No Action option can be assigned to a hash in IOC Management when you want to save the indicator for later action, but do not want to block or allow it at this time. This option will neither detect nor prevent the execution of the hash, but will keep it in the IOC list for future reference. The other options are either incorrect or not related to the No Action option. Reference: CrowdStrike Falcon User Guide, page 44.
NEW QUESTION # 54
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
- A. Machine Learning Exclusions
- B. Sensor Visibility Exclusion
- C. IOA Exclusions
- D. IOC Exclusions
Answer: C
Explanation:
Explanation
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 55
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
- A. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
- B. Contact support and request that they modify the Machine Learning settings to no longer include this detection
- C. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
- D. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
Answer: D
NEW QUESTION # 56
What is the goal of a Network Containment Policy?
- A. Gain more visibility into network activities
- B. Partition a network for privacy
- C. Limit the impact of a compromised host on the network
- D. Increase the aggressiveness of the assigned prevention policy
Answer: C
NEW QUESTION # 57
You want to create a detection-only policy. How do you set this up in your policy's settings?
- A. You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.
- B. Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.
- C. Select the "Detect-Only" template. Disable hash blocking and exclusions.
- D. Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.
Answer: D
NEW QUESTION # 58
When a host belongs to more than one host group, how is sensor update precedence determined?
- A. The highest precedence policy from the most important group is applied to the host
- B. All of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host
- C. Groups have no impact on sensor update policies
- D. Sensors of hosts that belong to more than one group must be manually updated
Answer: B
Explanation:
Explanation
The option that describes how sensor update precedence is determined when a host belongs to more than one host group is that all of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host. A Sensor Update policy is a policy that controls how and when the Falcon sensor is updated on a host. You can create and assign custom Sensor Update policies to different hosts or groups in your environment. Each Sensor Update policy has a precedence value, which determines its priority over other policies. The higher the precedence value, the higher the priority. If a host belongs to more than one host group, each with a different Sensor Update policy assigned, then all of the host's groups are examined in aggregate and the policy with highest precedence among them is applied to the host.
References: : [Falcon Administrator Learning Path | Infographic | CrowdStrike]
NEW QUESTION # 59
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
- A. \Program Files\My Program\My Files\*
- B. *\*
- C. *\Program Files\My Program\*\
- D. \Program Files\My Program\*
Answer: A
NEW QUESTION # 60
What is the primary purpose of using glob syntax in an exclusion?
- A. To specify a network share be excluded from detections
- B. To specify exclusion patterns to easily add files and folders and extensions to be prevented
- C. To specify exclusion patterns to easily exclude files and folders and extensions from detections
- D. To specify a Domain be excluded from detections
Answer: C
NEW QUESTION # 61
What can exclusions be applied to?
- A. Only the default host group
- B. Only the groups selected by the administrator
- C. Individual hosts selected by the administrator
- D. Either all hosts or specified groups
Answer: D
Explanation:
Explanation
The option that describes what exclusions can be applied to is that exclusions can be applied to either all hosts or specified groups. An exclusion is a rule that defines what files, folders, processes, IP addresses, or domains should be excluded from detection or prevention by the Falcon sensor. You can create and manage exclusions in the Exclusions page in the Falcon console. You can apply exclusions to either all hosts in your environment or to specific host groups that you select. You cannot apply exclusions to individual hosts selected by the administrator.
References: : [Cybersecurity Resources | CrowdStrike]
NEW QUESTION # 62
What command should be run to verify if a Windows sensor is running?
- A. ps -ef | grep falcon
- B. sc query csagent
- C. regedit myfile.reg
- D. netstat -f
Answer: B
NEW QUESTION # 63
What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?
- A. Event trigger(s)
- B. Trigger, condition(s) and action(s)
- C. Predefined workflow template(s)
- D. For - While statement(s)
Answer: B
NEW QUESTION # 64
Once an exclusion is saved, what can be edited in the future?
- A. All parts of the exclusion can be changed
- B. The exclusion pattern cannot be changed
- C. Only the options to "Detect/Block" and/or "File Extraction" can be changed
- D. Only the selected groups and hosts to which the exclusion is applied can be changed
Answer: A
NEW QUESTION # 65
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
- A. Falcon Ul Audit Trail
- B. Custom Alert History
- C. Workflow Audit log
- D. Workflow Execution log
Answer: D
Explanation:
Explanation
The place where you can find the history of the successes and failures for any Falcon Fusion workflows is the Workflow Execution log. The Workflow Execution log in the Workflow Management option allows you to view the status and results of workflow executions triggered by detection events. You can filter the log by workflow name, status, start and end time, and detection ID. You can also view the details of each execution, including the actions performed, the output received, and any errors encountered. This log can help you troubleshoot potential failures or issues with your workflows1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 66
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?
- A. 60 Days
- B. 75 Days
- C. 45 Days
- D. 90 Days
Answer: D
Explanation:
Explanation
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform. You can restore an inactive host from the Trash page if it becomes active again within 90 days1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 67
Which Real Time Response role will allow you to see all analyst session details?
- A. Real Time Response -Active Responder
- B. None of the Real Time Response roles allows this
- C. Real Time Response - Read-Only Analyst
- D. Real Time Response -Administrator
Answer: D
Explanation:
Explanation
The Real Time Response role that will allow you to see all analyst session details is Real Time Response
-Administrator. A Real Time Response -Administrator is a role that has full access and control over the Real Time Response feature in Falcon, which allows you to remotely access and investigate hosts in real time. A Real Time Response -Administrator can view all analyst session details, such as session ID, host name, start and end time, commands executed, and output received. A Real Time Response -Administrator can also create, modify, delete, and assign scripts and commands to other analysts2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 68
What best describes the relationship between Sensor Update policies and Operating Systems?
- A. Windows has its own Sensor Update polices. But Mac and Linux share Sensor Update policies
- B. Windows and Mac share Sensor Update policies. Linux requires its own set of polices based on the different kernel versions
- C. Sensor Update polices are not Operating System specific. One policy can be applied to all Operating Systems
- D. A Sensor Update policy must be configured for each Operating System (Windows, Mac, Linux)
Answer: D
Explanation:
Explanation
The option that describes the relationship between Sensor Update policies and Operating Systems is that a Sensor Update policy must be configured for each Operating System (Windows, Mac, Linux). This option is essentially a repetition of question 141 and its answer. Sensor Update policies are specific to each operating system type, as different operating systems have different sensor versions, features, and requirements. Therefore, you need to create and assign separate Sensor Update policies for each operating system type in your environment1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 69
What is the purpose of the Machine-Learning Prevention Monitoring Report?
- A. It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious
- B. It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
- C. It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
- D. It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
Answer: D
Explanation:
Explanation
Machine-Learning Prevention Monitoring dashboard: Use this dashboard to view malware that would have been blocked in your environment over the selected timeframe based on different Machine Learning Prevention settings (Cautious, Moderate, Aggressive or Extra Aggressive).
NEW QUESTION # 70
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
- A. Computer ID (CID)
- B. Agent ID (AID)
- C. Security ID (SID)
- D. Endpoint ID (EID)
Answer: B
NEW QUESTION # 71
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Explanation
There are three "Auto" sensor version update options available for Windows Sensor Update Policies: Auto - N-1, Auto - TEST-QA and Auto - Latest. These options allow the administrator to automatically update the sensor version to the previous stable version, the latest test version or the latest stable version, respectively.
Reference: [CrowdStrike Falcon User Guide], page 38.
NEW QUESTION # 72
......
100% Guarantee Download CCFA-200 Exam Dumps PDF Q&A: https://exams4sure.pass4sures.top/CrowdStrike-Certified-Falcon-Administrator/CCFA-200-testking-braindumps.html