[Nov-2024] 100% Guarantee Download CCFA-200 Exam Dumps PDF Q&A [Q48-Q73]

Share

[Nov-2024] 100% Guarantee Download CCFA-200 Exam Dumps PDF Q&A

Kickstart your Career with Real  Updated Questions

NEW QUESTION # 48
Why would you assign hosts to a static group instead of a dynamic group?

  • A. You want the group to contain hosts from multiple operating systems
  • B. You do not want the group membership to change automatically
  • C. You need hosts to be automatically assigned to a group
  • D. You are managing more than 1000 hosts

Answer: B

Explanation:
Explanation
The reason why you would assign hosts to a static group instead of a dynamic group is that you do not want the group membership to change automatically. A Static Group is a group that requires manual assignment or removal of hosts. A Static Group will not update its membership based on any criteria or filters. This way, you can have more control over which hosts belong to the group and prevent any unwanted changes1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 49
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?

  • A. \Device\HarddiskVolume2\*.exe -SingleArgument www.badguydomain.com /kill
  • B. badguydomain\.com.*
  • C. Custom IOA rules cannot be created for domains
  • D. .*badguydomain.com.*

Answer: A


NEW QUESTION # 50
Once an exclusion is saved, what can be edited in the future?

  • A. All parts of the exclusion can be changed
  • B. Only the options to "Detect/Block" and/or "File Extraction" can be changed
  • C. Only the selected groups and hosts to which the exclusion is applied can be changed
  • D. The exclusion pattern cannot be changed

Answer: A


NEW QUESTION # 51
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

  • A. 60 Days
  • B. 90 Days
  • C. 75 Days
  • D. 45 Days

Answer: B

Explanation:
Explanation
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform. You can restore an inactive host from the Trash page if it becomes active again within 90 days1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 52
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?

  • A. Edit the Default Response Policy and add the host group to the exceptions list under "Real Time Functionality"
  • B. Edit the Default Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
  • C. Create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
  • D. Create a new Response Policy and add the host name to the exceptions list under "Real Time Functionality"

Answer: C

Explanation:
Explanation
The administrator can create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group that contains the servers that are not allowed to be accessed remotely. This will disable RTR only on those hosts, while keeping it enabled for the rest of the hosts. Editing the Default Response Policy or adding exceptions will not achieve the desired result. Reference: CrowdStrike Falcon User Guide, page 35.


NEW QUESTION # 53
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?

  • A. Minimal
  • B. Cautious
  • C. Moderate
  • D. Aggressive

Answer: B

Explanation:
Explanation
The Machine Learning (ML) slider that will only detect or prevent high confidence malicious items is Cautious. The ML slider allows you to adjust the level of sensitivity and aggressiveness of the Falcon sensor's ML engine, which uses artificial intelligence to identify and stop unknown threats. The Cautious setting will enable the sensor to detect and prevent only high-confidence malicious events, while allowing low-confidence events to run without interference. This setting will also generate less noise and false positives than higher settings, such as Moderate or Extra Aggressive1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 54
When a user initiates a sensor installs, where can the logs be found?

  • A. % LOCALAPP D ATA%\Tem p
  • B. %LOCALAPPDATA%\Logs
  • C. %SYSTEMROOT%\Logs
  • D. %SYSTEMROOT%\Temp

Answer: D

Explanation:
Explanation
When a user initiates a sensor install, the logs can be found in %SYSTEMROOT%\Temp. This folder contains temporary files and folders created by the system or applications, including the sensor installation logs. The sensor installation logs have names that start with CSFalconContainer and end with .log, such as CSFalconContainer-2023-08-31_11-23-21.log. These logs can help you troubleshoot any issues or errors that may occur during the sensor installation process3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 55
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?

  • A. PowerShell
  • B. Linux Sub-System
  • C. Deep packet inspection
  • D. Windows Proxy

Answer: C

Explanation:
Explanation
The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 56
What can the Quarantine Manager role do?

  • A. Manage detection settings
  • B. Manage and change prevention settings
  • C. Manage quarantined files to release and download
  • D. Manage roles and users

Answer: C

Explanation:
Explanation
The Quarantine Manager role can manage quarantined files to release and download. This role allows users to view and search quarantined files, as well as release them from quarantine or download them for further analysis. The other roles do not have this capability. Reference: [CrowdStrike Falcon User Guide], page 19.


NEW QUESTION # 57
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?

  • A. Adware and Potentially Unwanted Program detection and prevention
  • B. Next-Gen Antivirus (NGAV) protection
  • C. Real-time offline protection
  • D. Identification and analysis of unknown executables

Answer: D


NEW QUESTION # 58
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?

  • A. **baddomain\. xyz|baddomain\. xyz**
  • B. Custom IOA rules cannot be created for domains
  • C. *\.baddomain\.xyz|baddomain\. xyz
  • D. *baddomain\. xyz|baddomain\. xyz. *

Answer: C

Explanation:
Explanation
The syntax that would be best for detecting or preventing on all subdomains as well is
*.baddomain.xyz|baddomain. xyz. This syntax will match any domain that ends with .baddomain.xyz or is exactly baddomain.xyz. The * wildcard will match any characters before the dot, and the | operator will match either side of the expression. This syntax can be used in a Custom IOC or a Custom IOA rule to detect or prevent network connections to malicious domains1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 59
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?

  • A. Sensor Report
  • B. Falcon UI Audit Trail
  • C. Machine Learning Prevention Monitoring
  • D. Machine Learning Debug

Answer: C


NEW QUESTION # 60
When a host is placed in Network Containment, which of the following is TRUE?

  • A. The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and traffic allowed in the Firewall Policy
  • B. The host machine is unable to send or receive any network traffic
  • C. The host machine is unable to send or receive network traffic outside of the local network
  • D. The host machine is unable to send or receive network traffic except to/from the Falcon Cloud and any resources allowlisted in the Containment Policy

Answer: D

Explanation:
Explanation
When a host is placed in Network Containment, the host machine is unable to send or receive network traffic except to/from the Falcon Cloud and any resources allowlisted in the Containment Policy. This allows users to isolate a host from the network, while still allowing it to communicate with the Falcon Cloud and other essential services. The other options are either incorrect or not true of Network Containment.
Reference: CrowdStrike Falcon User Guide, page 40.


NEW QUESTION # 61
How do you assign a policy to a specific group of hosts?

  • A. Create a group containing the desired hosts using "Dynamic Assignment." Go to the Assigned Host Groups tab of the desired policy and select criteria such as OU, OS, Hostname pattern, etc.
  • B. Create a group containing the desired hosts using "Static Assignment." Go to the Assigned Host Groups tab of the desired policy and dick "Add groups to policy." Select the desired Group(s).
  • C. On the Assignment tab of the desired policy, select "Static" assignment. From the next window, select the desired hosts (using fitters if needed) and click Add.
  • D. Assign a tag to the desired hosts in Host Management. Create a group with an assignment rule based on that tag. Go to the Assignment tab of the desired policy and click "Add Groups to Policy." Select the desired Group(s).

Answer: B

Explanation:
Explanation
The administrator can assign a policy to a specific group of hosts by creating a group containing the desired hosts using "Static Assignment." Then, go to the Assigned Host Groups tab of the desired policy and click
"Add groups to policy." Select the desired Group(s). This will apply the policy to the selected group(s) of hosts. The other options are either incorrect or not applicable to static assignment. Reference: [CrowdStrike Falcon User Guide], page 33.


NEW QUESTION # 62
How do you disable all detections for a host?

  • A. Create an exclusion rule and apply it to the machine or group of machines
  • B. Contact support and provide them with the Agent ID (AID) for the machine and they will put it on the Disabled Hosts list in your Customer ID (CID)
  • C. You cannot disable all detections on individual hosts as it would put them at risk
  • D. In Host Management, select the host and then choose the option to Disable Detections

Answer: D


NEW QUESTION # 63
What impact does disabling detections on a host have on an API?

  • A. Endpoints with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
  • B. Endpoints cannot have their detections disabled individually
  • C. Endpoints with detections disabled will not alert on anything until detections are enabled again
  • D. DetectionSummaryEvent stops sending to the Streaming API for that host

Answer: A


NEW QUESTION # 64
How do you assign a Prevention policy to one or more hosts?

  • A. Create a new policy and assign it directly to those hosts on the Host Management page
  • B. Create a new policy and assign it directly to those hosts on the Prevention policy page
  • C. Ensure the hosts are in a group and assign that group to a custom Prevention policy
  • D. Modify the users roles on the User Management page

Answer: C


NEW QUESTION # 65
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?

  • A. Re-create the API client using the exact name to see the API client secret
  • B. Enable the Client Secret column to reveal the API client secret
  • C. The API client secret can be viewed from the Edit API client pop-up box
  • D. The API client secret cannot be retrieved after it has been created

Answer: B


NEW QUESTION # 66
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?

  • A. Edit the Default Response Policy and add the host group to the exceptions list under "Real Time Functionality"
  • B. Edit the Default Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
  • C. Create a new Response Policy, toggle the "Real Time Response" switch off and assign the policy to the host group
  • D. Create a new Response Policy and add the host name to the exceptions list under "Real Time Functionality"

Answer: C


NEW QUESTION # 67
What is the primary purpose of using glob syntax in an exclusion?

  • A. To specify exclusion patterns to easily add files and folders and extensions to be prevented
  • B. To specify exclusion patterns to easily exclude files and folders and extensions from detections
  • C. To specify a network share be excluded from detections
  • D. To specify a Domain be excluded from detections

Answer: B

Explanation:
Explanation
Glob syntax is used to specify exclusion patterns to easily exclude files and folders and extensions from detections. Glob syntax allows you to use wildcards (*) and ranges ([a-z]) to match multiple characters or values in a file path or name. For example, you can use glob syntax to exclude all files with .exe extension in a folder by using C:\Folder*.exe as an exclusion pattern2.
References: 2: Cybersecurity Resources | CrowdStrike


NEW QUESTION # 68
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?

  • A. Utilize the Detection Resolution Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detection Resolution History" section
  • B. Utilize the Detection Activity Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detections by Host" section
  • C. In the Investigate module, access the Detection Activity page. Use the filters to focus on the appropriate hostname and time, then export the results
  • D. Go to Host Management in the Host page. Select the host and use the Export Detections button

Answer: C


NEW QUESTION # 69
On which page of the Falcon console would you create sensor groups?

  • A. User management
  • B. Sensor update policies
  • C. Host groups
  • D. Host management

Answer: C


NEW QUESTION # 70
When creating a Host Group for all Workstations in an environment, what is the best method to ensure all workstation hosts are added to the group?

  • A. Create a Dynamic Group and Import All Workstations
  • B. Create a Static Group with Type=Workstation Assignment
  • C. Create a Dynamic Group with Type=Workstation Assignment
  • D. Create a Static Group and Import all Workstations

Answer: C


NEW QUESTION # 71
Which role will allow someone to manage quarantine files?

  • A. Falcon Analyst - Read Only
  • B. Detections Exceptions Manager
  • C. Falcon Security Lead
  • D. Endpoint Manager

Answer: B


NEW QUESTION # 72
Which of the following is NOT an available filter on the Hosts Management page?

  • A. OS Version
  • B. Group
  • C. Username
  • D. Hostname

Answer: A


NEW QUESTION # 73
......

Earn Quick And Easy Success With CCFA-200 Dumps: https://examsdocs.dumpsquestion.com/CCFA-200-exam-dumps-collection.html