Get The Most Updated CCFA-200 Dumps To CrowdStrike Certified Falcon Administrator Certification [Q33-Q52]

Share

Get The Most Updated CCFA-200 Dumps To CrowdStrike Certified Falcon Administrator Certification

CrowdStrike Certified CCFA-200  Dumps Questions Valid CCFA-200 Materials

NEW QUESTION 33
If a user wanted to install an older version of the Falcon sensor, how would they find the older installer file?

  • A. By installing the current sensor and clicking the "downgrade" button during the install
  • B. By emailing CrowdStrike support at [email protected]
  • C. By clicking on "Older versions" links under the Host setup and management > Deploy > Sensor downloads
  • D. Older versions of the sensor are not available for download

Answer: C

 

NEW QUESTION 34
Which is a filter within the Host setup and management > Host management page?

  • A. BIOS Version
  • B. User name
  • C. Locality
  • D. OU

Answer: A

 

NEW QUESTION 35
How do you find a list of inactive sensors?

  • A. The Falcon platform does not provide reporting for inactive sensors
  • B. Run the Inactive Sensor Report in the Host setup and management option
  • C. Run the Sensor Aging Report within the Investigate option
  • D. A sensor is always considered active until removed by an Administrator

Answer: C

 

NEW QUESTION 36
When the Notify End Users policy setting is turned on, which of the following is TRUE?

  • A. End users will not be notified as we would not want to notify a malicious actor of a detection. This setting does not exist
  • B. End users will be immediately notified via a pop-up that their machine is in-network isolation
  • C. End users will receive a pop-up allowing them to confirm or refuse a pending quarantine
  • D. End-users receive a pop-up notification when a prevention action occurs

Answer: D

 

NEW QUESTION 37
Which role is required to manage groups and policies in Falcon?

  • A. Falcon Host Analyst
  • B. Falcon Host Security Lead
  • C. Prevention Hashes Manager
  • D. Falcon Host Administrator

Answer: D

 

NEW QUESTION 38
Which of the following best describes the Default Sensor Update policy?

  • A. The Default Sensor Update policy is disabled by default
  • B. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature
  • C. The Default Sensor Update policy is only used for testing sensor updates
  • D. The Default Sensor Update policy is a "catch-all" policy

Answer: D

 

NEW QUESTION 39
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 40
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?

  • A. Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"
  • B. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.
  • C. Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running
  • D. Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"

Answer: B

 

NEW QUESTION 41
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?

  • A. Real Time Responder - Active Responder
  • B. Falcon Analyst - Read Only
  • C. Real Time Responder - Read Only Analyst
  • D. Remediation Manager

Answer: B

 

NEW QUESTION 42
Which of the following is a valid step when troubleshooting sensor installation failure?

  • A. Disable SSL and TLS on the host
  • B. Delete any available application crash log files
  • C. Enable the Windows firewall
  • D. Confirm all required services are running on the system

Answer: D

 

NEW QUESTION 43
How are user permissions set in Falcon?

  • A. Permissions are token-based. Users request access to a defined set of permissions and an administrator adds their token to the set of permissions
  • B. An administrator selects individual granular permissions from the Falcon Permissions List during user creation
  • C. Permissions are assigned to a User Group and then users are assigned to that group, thereby inheriting those permissions
  • D. Pre-defined permissions are assigned to sets called roles. Users can be assigned multiple roles based on job function and they assume a cumulative set of permissions based on those assignments

Answer: D

 

NEW QUESTION 44
Why is the ability to disable detections helpful?

  • A. It gives users the ability to uninstall the sensor from a host
  • B. It gives users the ability to set up hosts to test detections and later remove them from the console
  • C. It gives users the ability to remove all data from hosts that have been uninstalled
  • D. It gives users the ability to allowlist a false positive detection

Answer: D

 

NEW QUESTION 45
To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

  • A. Using IOC management, import the list of hashes and IP addresses and set the action to No Action
  • B. Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block
  • C. Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead
  • D. Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only

Answer: B

 

NEW QUESTION 46
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20 minute default provisioning window?

  • A. Timeout=0
  • B. ExtendedWindow=1
  • C. Timeout=30
  • D. ProvNoWait=1

Answer: C

 

NEW QUESTION 47
Which of the following can a Falcon Administrator edit in an existing user's profile?

  • A. Working groups
  • B. Email address
  • C. Phone number
  • D. First or Last name

Answer: A

 

NEW QUESTION 48
In order to quarantine files on the host, what prevention policy settings must be enabled?

  • A. Malware Protection and Custom Execution Blocking must be enabled
  • B. Behavior-Based Threat Prevention sliders and Advanced Remediation Actions must be enabled
  • C. Malware Protection and Windows Anti-Malware Execution Blocking must be enabled
  • D. Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be enabled

Answer: C

 

NEW QUESTION 49
Why would you assign hosts to a static group instead of a dynamic group?

  • A. You want the group to contain hosts from multiple operating systems
  • B. You do not want the group membership to change automatically
  • C. You are managing more than 1000 hosts
  • D. You need hosts to be automatically assigned to a group

Answer: B

 

NEW QUESTION 50
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?

  • A. Maintenance token
  • B. Bulk update key
  • C. Agent ID (AID)
  • D. Customer ID (CID)

Answer: A

 

NEW QUESTION 51
Which of the following is TRUE of the Logon Activities Report?

  • A. Shows a graphical view of user logon activity and the hosts the user connected to
  • B. The report can be filtered by computer name
  • C. It gives a detailed list of all logon activity for users
  • D. It only gives a summary of the last logon activity for users

Answer: C

 

NEW QUESTION 52
......

CCFA-200 Premium PDF & Test Engine Files with 99 Questions & Answers: https://www.itexamsimulator.com/CCFA-200-brain-dumps.html

Current CCFA-200 Exam Dumps [2023] Complete CrowdStrike Exam Smoothly: https://drive.google.com/open?id=1T7J8-9gTp4yscHMbZ26y2o2bM5i8jIgE