Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the CrowdStrike CCSE CCSE-204 Questions and answers with Dumpstech

Exam CCSE-204 Premium Access

View all detail and faqs for the CCSE-204 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An event has the following fields:

Question # 1

Which CQL query will output the frequency of a unique set of ComputerName, UserName, CommandLine?

Options:

A.

#event_simpleName = ProcessRollup2 FileName = ssh.exe CommandLine = /\s-R\s.+\s-p/ | table([ComputerName, UserName, CommandLine]) | count()

B.

#event_simpleName = ProcessRollup2

| FileName = ssh.exe

| CommandLine = /\s-R\s.+\s-p/

| table([ComputerName, UserName, CommandLine], function=count())

C.

#event_simpleName = ProcessRollup2

| FileName = ssh.exe

| CommandLine = /\s-R\s.+\s-p/

| groupBy([ComputerName, UserName, CommandLine], function=count())

D.

#event_simpleName = ProcessRollup2 FileName = ssh.exe CommandLine = /\s-R\s.+\s-p/ | groupBy([ComputerName, UserName, CommandLine])

Questions # 2:

When deploying the Falcon Log Collector using the commands in the CrowdStrike Fleet Management interface, what is the correct service name?

Options:

A.

flc-api

B.

humio-collector

C.

logscale-collector

D.

flc-collector

Questions # 3:

Which Falcon LogScale Collector output format would you use if your downstream SIEM requires raw nested event data?

Options:

A.

Syslog

B.

CEF

C.

JSON

D.

LEEF

Questions # 4:

You need to import a pre-built workflow into Fusion SOAR to automate a part of your incident response process.

Which file format would you use?

Options:

A.

.CPP

B.

.JSON

C.

.PY

D.

.YAML

Questions # 5:

What is true about first-party data from the Falcon platform and its integration into Next-Gen SIEM?

Options:

A.

First-party data requires a log collector installation

B.

It is quickly ingested to Next-Gen SIEM via a third-party integration

C.

It is instantly accessible within Next-Gen SIEM

Questions # 6:

Which field is compliant with CrowdStrike Parsing Standard (CPS)?

Options:

A.

Parser.type

B.

#event.dataset

C.

#event.trigger

D.

Parser.name

Questions # 7:

Following the principle of least privilege, which is the appropriate role to grant a Falcon Next-Gen SIEM user the permissions to read case data and write XDR data while denying the permission to write case templates?

Options:

A.

NG SIEM Security Lead

B.

NG SIEM Analyst – Read Only

C.

NG SIEM Analyst

D.

NGSIEM Administrator

Questions # 8:

What are the four required CPS-compliant Event parser tags?

Options:

A.

event.category

event.kind

event.module

event.outcome

B.

event.category

event.dataset

event.kind

event.outcome

C.

event.dataset

event.kind

event.module

event.outcome

Questions # 9:

You are creating an AI-generated parser to process and normalize log data from various sources.

How would you ensure the parser accurately interprets and categorizes the log data?

Options:

A.

Ensure the parser has a minimum of 100 lines

B.

Create a set of log examples to match log patterns from different sources

C.

Write the parser in a high-level programming language (Python or Java)

Questions # 10:

You are performing a search query using data from the Falcon Sensor and third-party data connectors.

Which Advanced Event Search data source should you choose?

Options:

A.

All

B.

Falcon

C.

Third-party

D.

Custom

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions