
[Mar-2024] 100% Guarantee Download CCFA-200 Exam Dumps PDF Q&A
Kickstart your Career with Real Updated Questions
NEW QUESTION # 35
What can the Quarantine Manager role do?
- A. Manage quarantined files to release and download
- B. Manage detection settings
- C. Manage and change prevention settings
- D. Manage roles and users
Answer: A
NEW QUESTION # 36
You want to create a detection-only policy. How do you set this up in your policy's settings?
- A. You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.
- B. Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.
- C. Select the "Detect-Only" template. Disable hash blocking and exclusions.
- D. Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.
Answer: D
NEW QUESTION # 37
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
- A. Containment Policy
- B. Machine Learning Exclusions
- C. USB Device Policy
- D. Firewall Rule Group
Answer: A
NEW QUESTION # 38
How are user permissions set in Falcon?
- A. An administrator selects individual granular permissions from the Falcon Permissions List during user creation
- B. Permissions are token-based. Users request access to a defined set of permissions and an administrator adds their token to the set of permissions
- C. Pre-defined permissions are assigned to sets called roles. Users can be assigned multiple roles based on job function and they assume a cumulative set of permissions based on those assignments
- D. Permissions are assigned to a User Group and then users are assigned to that group, thereby inheriting those permissions
Answer: C
NEW QUESTION # 39
When creating a Host Group for all Workstations in an environment, what is the best method to ensure all workstation hosts are added to the group?
- A. Create a Static Group and Import all Workstations
- B. Create a Dynamic Group with Type=Workstation Assignment
- C. Create a Static Group with Type=Workstation Assignment
- D. Create a Dynamic Group and Import All Workstations
Answer: B
NEW QUESTION # 40
Which role will allow someone to manage quarantine files?
- A. Falcon Analyst - Read Only
- B. Detections Exceptions Manager
- C. Endpoint Manager
- D. Falcon Security Lead
Answer: D
Explanation:
Explanation
The role that will allow someone to manage quarantine files is Falcon Security Lead. This role allows users to view and manage quarantined files, as well as release them from quarantine or download them for further analysis. The other roles do not have this capability. Reference: CrowdStrike Falcon User Guide, page 19.
NEW QUESTION # 41
With Custom Alerts, it is possible to __________.
- A. be alerted to activity in real-time
- B. configure prevention actions for alerting
- C. receive an alert in an email
- D. schedule the alert to run at any interval
Answer: C
Explanation:
Explanation
The reporting interval is predefined and cannot be changed. You can only enable/disable the custom alert feature and add/remove recipient email client for the alert/detection.
NEW QUESTION # 42
After agent installation, an agent opens a permanent___connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is terminated.
- A. HTTP
- B. TCP
- C. TLS
- D. SSH
Answer: C
Explanation:
Explanation
After agent installation, an agent opens a permanent TLS connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is terminated. TLS (Transport Layer Security) is a protocol that provides secure and encrypted communication between the agent and the Falcon cloud. Port
443 is the standard port for HTTPS (Hypertext Transfer Protocol Secure) traffic. The agent uses this connection to send and receive data, commands, policies, and updates from the Falcon cloud2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 43
What impact does disabling detections on a host have on an API?
- A. Endpoints with detections disabled will not alert on anything until detections are enabled again
- B. DetectionSummaryEvent stops sending to the Streaming API for that host
- C. Endpoints with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
- D. Endpoints cannot have their detections disabled individually
Answer: C
NEW QUESTION # 44
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
- A. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
- B. Contact support and request that they modify the Machine Learning settings to no longer include this detection
- C. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
- D. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
Answer: C
Explanation:
Explanation
to match any number of characters including none while not matching beyond path separators (\ or /) and double asterisks are used to recursively match zero or more directories that fall under the current directory.
NEW QUESTION # 45
When a host belongs to more than one host group, how is sensor update precedence determined?
- A. The highest precedence policy from the most important group is applied to the host
- B. Sensors of hosts that belong to more than one group must be manually updated
- C. All of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host
- D. Groups have no impact on sensor update policies
Answer: C
Explanation:
Explanation
The option that describes how sensor update precedence is determined when a host belongs to more than one host group is that all of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host. A Sensor Update policy is a policy that controls how and when the Falcon sensor is updated on a host. You can create and assign custom Sensor Update policies to different hosts or groups in your environment. Each Sensor Update policy has a precedence value, which determines its priority over other policies. The higher the precedence value, the higher the priority. If a host belongs to more than one host group, each with a different Sensor Update policy assigned, then all of the host's groups are examined in aggregate and the policy with highest precedence among them is applied to the host.
References: : [Falcon Administrator Learning Path | Infographic | CrowdStrike]
NEW QUESTION # 46
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
- A. IOC Exclusions
- B. Machine Learning Exclusions
- C. Sensor Visibility Exclusion
- D. IOA Exclusions
Answer: D
Explanation:
Explanation
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 47
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
- A. Add a parallel action to send a custom email to your CISO
- B. Add a sequential action to send a custom email to your CISO
- C. Add the CISO's email to the existing action
- D. Clone the workflow and replace the existing email with your CISO's email
Answer: B
NEW QUESTION # 48
Where in the Falcon console can information about supported operating system versions be found?
- A. Discover module
- B. Support module
- C. Intelligence module
- D. Configuration module
Answer: B
NEW QUESTION # 49
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?
- A. Real Time Responder - Read Only Analyst
- B. Real Time Responder - Active Responder
- C. Falcon Analyst - Read Only
- D. Remediation Manager
Answer: C
NEW QUESTION # 50
Which of the following is TRUE regarding disabling detections for a host?
- A. The detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled
- B. After disabling detections, the data for all existing detections prior to disabling detections is removed from the Event Search
- C. After disabling detections, the host will operate in Reduced Functionality Mode (RFM) until detections are enabled
- D. The DetectionSummaryEvent continues being sent to the Streaming API for that host
Answer: A
Explanation:
Explanation
The option that is true regarding disabling detections for a host is that the detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled. This option is essentially a repetition of question 127 and its answer. Disabling detections for a host will remove any existing detections for that host from the console and prevent any new detections from appearing in the console until detections are enabled again1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 51
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
- A. Sensor version updates off
- B. Auto - N-1
- C. Auto - TEST-QA
- D. Specific sensor version number
Answer: D
Explanation:
Explanation
The administrator can choose a specific sensor version number in the Sensor Update policy to manually control when the sensor version is upgraded or downgraded. This will allow the Falcon Cloud to push out sensor version changes, but only when the administrator changes the version number in the policy. The other options will either automate the sensor version updates or turn them off completely. Reference: [CrowdStrike Falcon User Guide], page 38.
NEW QUESTION # 52
Which of the following best describes the Default Sensor Update policy?
- A. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature
- B. The Default Sensor Update policy is disabled by default
- C. The Default Sensor Update policy is only used for testing sensor updates
- D. The Default Sensor Update policy is a "catch-all" policy
Answer: D
Explanation:
Explanation
The Default Sensor Update policy is a "catch-all" policy. This means that any host that is not assigned to a specific sensor update policy will inherit the settings from the Default Sensor Update policy. The Default Sensor Update policy is enabled by default and has the "Uninstall and maintenance protection" feature turned on. You can modify the settings of the Default Sensor Update policy, but you cannot delete or disable it2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 53
......
Earn Quick And Easy Success With CCFA-200 Dumps: https://examcollection.prep4king.com/CCFA-200-latest-questions.html

