
CCFA-200 Exam Preparation Material with New CCFA-200 Dumps Questions
CCFA-200 2024 Training With 152 QA's
NEW QUESTION # 45
Where in the Falcon console can information about supported operating system versions be found?
- A. Configuration module
- B. Support module
- C. Discover module
- D. Intelligence module
Answer: B
NEW QUESTION # 46
What is the purpose of a containment policy?
- A. To define allowed IP addresses over which your hosts will communicate when contained
- B. To define the duration of Network Containment
- C. To define which Falcon analysts can contain endpoints
- D. To define the trigger under which a machine is put in Network Containment (e.g. a critical detection)
Answer: D
NEW QUESTION # 47
What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?
- A. Microsoft updates
- B. Falcon sensors installing an update
- C. Notifications have been disabled on that host sensor
- D. Falcon console updates are pending
Answer: C
NEW QUESTION # 48
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
- A. Contact support and request that they modify the Machine Learning settings to no longer include this detection
- B. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
- C. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
- D. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
Answer: D
NEW QUESTION # 49
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
- A. Deep packet inspection
- B. PowerShell
- C. Linux Sub-System
- D. Windows Proxy
Answer: A
Explanation:
Explanation
The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 50
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
- A. *\Program Files\My Program\*\
- B. \Program Files\My Program\My Files\*
- C. *\*
- D. \Program Files\My Program\*
Answer: B
NEW QUESTION # 51
Where in the Falcon console can information about supported operating system versions be found?
- A. Configuration module
- B. Support module
- C. Discover module
- D. Intelligence module
Answer: B
Explanation:
Explanation
Information about supported operating system versions can be found in the Support module in the Falcon console. This module provides access to various support resources, such as documentation, downloads, FAQs, release notes and system status. One of the documents available in this module is the CrowdStrike Sensor Compatibility List, which lists the supported operating system versions for each sensor type and platform. The other options are either incorrect or not related to finding information about supported operating system versions. Reference: CrowdStrike Falcon User Guide, page 26.
NEW QUESTION # 52
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
- A. Prevention Policy Audit Trail
- B. Prevention Policy Debug
- C. Prevention Hashes Ignored
- D. Machine-Learning Prevention Monitoring
Answer: A
NEW QUESTION # 53
Which of the following is TRUE of the Logon Activities Report?
- A. It gives a detailed list of all logon activity for users
- B. It only gives a summary of the last logon activity for users
- C. Shows a graphical view of user logon activity and the hosts the user connected to
- D. The report can be filtered by computer name
Answer: A
NEW QUESTION # 54
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?
- A. Aggressive
- B. Moderate
- C. Cautious
- D. Minimal
Answer: C
Explanation:
Explanation
The Machine Learning (ML) slider that will only detect or prevent high confidence malicious items is Cautious. The ML slider allows you to adjust the level of sensitivity and aggressiveness of the Falcon sensor's ML engine, which uses artificial intelligence to identify and stop unknown threats. The Cautious setting will enable the sensor to detect and prevent only high-confidence malicious events, while allowing low-confidence events to run without interference. This setting will also generate less noise and false positives than higher settings, such as Moderate or Extra Aggressive1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 55
Which of the following is TRUE regarding Falcon Next-Gen AntiVirus (NGAV)?
- A. Falcon NGAV relies on signature-based detections
- B. The Detection sliders cannot be set to a value less aggressive than the Prevention sliders
- C. Falcon NGAV is not a replacement for Windows Defender or other antivirus programs
- D. Activating Falcon NGAV will also enable all detection and prevention settings in the entire policy
Answer: B
Explanation:
Explanation
The Detection sliders cannot be set to a value less aggressive than the Prevention sliders in Falcon Next-Gen AntiVirus (NGAV). This is because prevention is a subset of detection, and it would not make sense to prevent threats that are not detected. The other options are either incorrect or not true of Falcon NGAV. Reference:
[CrowdStrike Falcon User Guide], page 35.
NEW QUESTION # 56
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
- A. Add the CISO's email to the existing action
- B. Add a sequential action to send a custom email to your CISO
- C. Add a parallel action to send a custom email to your CISO
- D. Clone the workflow and replace the existing email with your CISO's email
Answer: B
NEW QUESTION # 57
What can the Quarantine Manager role do?
- A. Manage detection settings
- B. Manage quarantined files to release and download
- C. Manage roles and users
- D. Manage and change prevention settings
Answer: B
NEW QUESTION # 58
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A. The network protocols are different for each host OS
- B. There may be special considerations for each OS
- C. It is an auditing requirement
- D. To assist with testing and tracking sensor rollouts
Answer: B
Explanation:
Explanation
https://www.crowdstrike.com/blog/tech-center/how-to-manage-policies-in-falcon/
NEW QUESTION # 59
Why would you assign hosts to a static group instead of a dynamic group?
- A. You do not want the group membership to change automatically
- B. You are managing more than 1000 hosts
- C. You need hosts to be automatically assigned to a group
- D. You want the group to contain hosts from multiple operating systems
Answer: A
Explanation:
Explanation
The reason why you would assign hosts to a static group instead of a dynamic group is that you do not want the group membership to change automatically. A Static Group is a group that requires manual assignment or removal of hosts. A Static Group will not update its membership based on any criteria or filters. This way, you can have more control over which hosts belong to the group and prevent any unwanted changes1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 60
When would the No Action option be assigned to a hash in IOC Management?
- A. There is no such option as No Action available in the Falcon console
- B. Add the indicator to your blocklist and show it as a detection
- C. When you want to save the indicator for later action, but do not want to block or allow it at this time
- D. Add the indicator to your allowlist and do not detect it
Answer: C
NEW QUESTION # 61
Under which scenario can Sensor Tags be assigned?
- A. While installing a sensor
- B. While managing hosts in the Falcon console
- C. While updating a sensor in the Falcon console
- D. While triaging a detection
Answer: A
Explanation:
Explanation
Check in documentation, there are two kind of tags, the Falcon Grouping Tags that can be managed in falcon console or API and the Sensor Grouping Tags that are configured as parameter in cli, that kind of tags can be diferentiated because it appears with the prefix SensorGroupingTags followed with the name of the tag. If you want to modify a sensor tag is necessary change a registry key value and reboot the device or waiting until the sensor is upgraded.
NEW QUESTION # 62
When the Notify End Users policy setting is turned on, which of the following is TRUE?
- A. End-users receive a pop-up notification when a prevention action occurs
- B. End users will be immediately notified via a pop-up that their machine is in-network isolation
- C. End users will receive a pop-up allowing them to confirm or refuse a pending quarantine
- D. End users will not be notified as we would not want to notify a malicious actor of a detection. This setting does not exist
Answer: A
NEW QUESTION # 63
What is the goal of a Network Containment Policy?
- A. Limit the impact of a compromised host on the network
- B. Partition a network for privacy
- C. Gain more visibility into network activities
- D. Increase the aggressiveness of the assigned prevention policy
Answer: A
Explanation:
Explanation
The goal of a Network Containment Policy is to limit the impact of a compromised host on the network. This policy allows users to isolate a host from the network, while still allowing it to communicate with the Falcon Cloud and other essential services. This can help prevent further damage or data exfiltration from a compromised host. The other options are either incorrect or not related to the policy. Reference: [CrowdStrike Falcon User Guide], page 40.
NEW QUESTION # 64
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
- A. Script-based Execution Monitoring
- B. Interpreter-Only
- C. Engine (Full Visibility)
- D. Additional User Mode Data
Answer: A
Explanation:
Explanation
Turn on the Script-Based Execution Monitoring prevention policy setting to enable the "Falcon sensor to monitor the contents of scripts and shells that are popular mechanisms for executing malicious code on hosts.
This setting does not kill or block scripts."
Scripting languages:
Excel 4.0 macros
JScript
VBA Macros
VBScript
The Sensor Visibility setting that should be turned on within the Prevention policy settings to monitor suspicious VBA macros is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. VBA (Visual Basic for Applications) is a scripting language that can be embedded in Microsoft Office documents, such as Word or Excel. VBA macros can be used to automate tasks or perform actions within the documents, but they can also be abused by attackers to deliver malware or execute malicious code. Script-based Execution Monitoring can help detect and prevent such attacks by monitoring the contents of VBA macros for execution of malicious content.
References: : [Falcon Administrator Learning Path | Infographic | CrowdStrike]
NEW QUESTION # 65
What is the purpose of precedence with respect to the Sensor Update policy?
- A. Precedence applies to the Prevention policy and not to the Sensor Update policy
- B. Precedence ensures that conflicting policy settings are not set in the same policy
- C. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
- D. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
Answer: D
NEW QUESTION # 66
What is the maximum number of patterns that can be added when creating a new exclusion?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 67
What impact does disabling detections on a host have on an API?
- A. Endpoints with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
- B. Endpoints cannot have their detections disabled individually
- C. DetectionSummaryEvent stops sending to the Streaming API for that host
- D. Endpoints with detections disabled will not alert on anything until detections are enabled again
Answer: A
NEW QUESTION # 68
On which page of the Falcon console would you create sensor groups?
- A. Host management
- B. Host groups
- C. User management
- D. Sensor update policies
Answer: B
NEW QUESTION # 69
Which role will allow someone to manage quarantine files?
- A. Endpoint Manager
- B. Falcon Analyst - Read Only
- C. Falcon Security Lead
- D. Detections Exceptions Manager
Answer: C
Explanation:
Explanation
The role that will allow someone to manage quarantine files is Falcon Security Lead. This role allows users to view and manage quarantined files, as well as release them from quarantine or download them for further analysis. The other roles do not have this capability. Reference: CrowdStrike Falcon User Guide, page 19.
NEW QUESTION # 70
......
Quickly and Easily Pass CrowdStrike Exam with CCFA-200 real Dumps: https://www.torrentvce.com/CCFA-200-valid-vce-collection.html
CrowdStrike CCFA-200 Certification Exam Questions: https://drive.google.com/open?id=1dDXX9NP6G8W8stC2xxwhoyulPO2FSicK