Spring Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with Dumpstech

Exam CCFA-200b Premium Access

View all detail and faqs for the CCFA-200b exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

What least privilege role should be given to a user who needs to extract files with RTR?

Options:

A.

Real Time Responder - Active Responder

B.

Falcon Security Lead

C.

Falcon Investigator

D.

Real Time Responder - Administrator

Questions # 2:

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?

Options:

A.

Create an exclusion for the felix.dll file

B.

Create an IOA exclusion for C:\Users\Bob\DevCode\felix.dll

C.

Create a separate Host Group for development machines and apply a less restrictive policy

D.

Create a Custom IOC and set it to Allow for C:\Users\Bob\DevCode\felix.dll

Questions # 3:

Which report in Falcon can be used to determine the volume of blocked activity at a different prevention policy setting?

Options:

A.

Falcon Prevention Policy Debug

B.

Machine Learning Prevention Monitoring

C.

Prevention Policy Audit Trail

Questions # 4:

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

Options:

A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

B.

Implement an SVE on the particular host

C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done

D.

Use Real Time Response to kill the offending process on the server

Questions # 5:

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

Options:

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

Questions # 6:

When searching for a host network address, which IP notation should be used?

Options:

A.

10 10105,1010108

B.

1010102,10 10107

C.

192.168.5.1/24

D.

192 168 5 1-100

Questions # 7:

When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?

Options:

A.

Access Key and Secret Key

B.

Integration Key and Customer ID

C.

API Client and Secret Key

D.

OAuth2 Token and Client Secret

Questions # 8:

You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that it executes successfully?

Options:

A.

Trigger, Condition, Action

B.

Rule Type, Condition, Action

C.

Rule Type, Filter, Objective

D.

Trigger, Filter, Objective

Questions # 9:

How are prevention policies assigned to hosts in the Falcon platform?

Options:

A.

Through host group membership

B.

Through direct host assignment

C.

Through IP address ranges

D.

Through manual configuration

Questions # 10:

In order to quarantine files on the host, what prevention policy settings must be enabled?

Options:

A.

Malware Protection and Windows Anti-Malware Execution Blocking

B.

Next-Gen Antivirus Prevention sliders and “Quarantine & Security Center Registration”

C.

Malware Protection and Custom Execution Blocking

D.

Behavior-Based Threat Prevention sliders and Advanced Remediation Actions

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions