CrowdStrike Exam 2024 CCFA-200 Dumps Updated Questions UPDATED Dec-2024 [Q25-Q50]

Share

CrowdStrike Exam 2024 CCFA-200 Dumps Updated Questions UPDATED Dec-2024

Get The Most Updated CCFA-200 Dumps To CrowdStrike Certified Falcon Administrator Certification

NEW QUESTION # 25
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?

  • A. Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"
  • B. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.
  • C. Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running
  • D. Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"

Answer: B

Explanation:
Explanation
The best way to ensure that a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers are not allowed to run in your environment is to use IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking. This will allow Falcon to block the execution of these hashes on the hosts using this policy. The other options are either incorrect or not efficient to achieve this goal. Reference: [CrowdStrike Falcon User Guide], page 44.


NEW QUESTION # 26
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?

  • A. Operating System Groups
  • B. Custom IOA Rule Groups
  • C. Enterprise Groups
  • D. Custom IOC Groups

Answer: A


NEW QUESTION # 27
What is the purpose of the Machine-Learning Prevention Monitoring Report?

  • A. It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
  • B. It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
  • C. It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
  • D. It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

Answer: A

Explanation:
Explanation
Machine-Learning Prevention Monitoring dashboard: Use this dashboard to view malware that would have been blocked in your environment over the selected timeframe based on different Machine Learning Prevention settings (Cautious, Moderate, Aggressive or Extra Aggressive).


NEW QUESTION # 28
Which statement describes what is recommended for the Default Sensor Update policy?

  • A. The Default Sensor Update should be configured to always automatically upgrade to the latest sensor version
  • B. Since the Default Sensor Update policy is pre-configured with recommend settings out of the box, configuration of the Default Sensor Update policy is not required
  • C. The Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible
  • D. No configuration is required. Once a Custom Sensor Update policy is created the Default Sensor Update policy is disabled

Answer: C

Explanation:
Explanation
The statement that describes what is recommended for the Default Sensor Update policy is that the Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible. As explained in question 139, the Default Sensor Update policy is a "catch-all" policy that applies to any host that is not assigned to a specific Sensor Update policy.
Therefore, it is recommended that the Default Sensor Update policy should align to your organization's overall sensor updating practice, such as how frequently and how quickly you want to update your sensors. It is also recommended that you leverage the Auto N-1 and Auto N-2 configurations, which allow you to automatically update your sensors to the latest or second-latest sensor version without requiring manual intervention1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 29
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?

  • A. IP Allowlist Management
  • B. Maintenance Token
  • C. Response Policy
  • D. Containment Policy

Answer: A

Explanation:
Explanation
The option that would need to be configured to allow remote connections from specified IP's after network containing a host is IP Allowlist Management. IP Allowlist Management allows you to define a list of trusted IP addresses that can communicate with your contained hosts. This way, you can isolate a host from the network while still allowing your incident response team or other authorized parties to remotely connect to the host for investigation or remediation purposes2.
References: 2: Cybersecurity Resources | CrowdStrike


NEW QUESTION # 30
Which is a filter within the Host setup and management > Host management page?

  • A. BIOS Version
  • B. User name
  • C. OU
  • D. Locality

Answer: C

Explanation:
Explanation
OU (organizational unit) is a filter within the Host setup and management > Host management page. The Host management page allows you to view and manage all the hosts in your environment that have Falcon sensors installed. You can filter the hosts by hostname, group, OS version, sensor version, last seen date, health events, detections, and preventions. You can also filter by OU, which is a logical grouping of hosts based on their Active Directory domain structure1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 31
When troubleshooting the Falcon Sensor on Windows, what is the correct parameter to output the log directory to a specified file?

  • A. \log log.txt
  • B. /log log.txt
  • C. C:\CSSensorlnstall\LogFiles
  • D. LOG=log.txt

Answer: B

Explanation:
Explanation
The correct parameter to output the log directory to a specified file when troubleshooting the Falcon Sensor on Windows is /log log.txt. This parameter will create a log file named log.txt in the same folder where you run the sensor installation command. The log file will contain information about the sensor installation process, such as the parameters used, the actions performed, and any errors encountered3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 32
What must an admin do to reset a user's password?

  • A. From User Management, the administrator must rebuild the account as the certificate for user specific private/public key generation is no longer valid
  • B. From User Management, select "Update Account" and manually create a new password for the affected user account
  • C. From User Management, open the account details for the affected user and select "Generate New Password"
  • D. From User Management, select "Reset Password" from the three dot menu for the affected user account

Answer: D

Explanation:
Explanation
The administrator can reset a user's password by selecting "Reset Password" from the three dot menu for the affected user account in the User Management page. This will generate a new password and send it to the user's email address. The other options are either incorrect or not available. Reference: CrowdStrike Falcon User Guide, page 25.


NEW QUESTION # 33
Under which scenario can Sensor Tags be assigned?

  • A. While managing hosts in the Falcon console
  • B. While installing a sensor
  • C. While triaging a detection
  • D. While updating a sensor in the Falcon console

Answer: B

Explanation:
Explanation
Check in documentation, there are two kind of tags, the Falcon Grouping Tags that can be managed in falcon console or API and the Sensor Grouping Tags that are configured as parameter in cli, that kind of tags can be diferentiated because it appears with the prefix SensorGroupingTags followed with the name of the tag. If you want to modify a sensor tag is necessary change a registry key value and reboot the device or waiting until the sensor is upgraded.


NEW QUESTION # 34
The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.

  • A. the last time the user's password was set
  • B. the account type for the user (e.g. Domain Administrator, Local User)
  • C. the logon type (e.g. interactive, service)
  • D. all hosts the user logged into

Answer: A


NEW QUESTION # 35
When a user initiates a sensor installs, where can the logs be found?

  • A. %LOCALAPPDATA%\Logs
  • B. %SYSTEMROOT%\Logs
  • C. %SYSTEMROOT%\Temp
  • D. % LOCALAPP D ATA%\Tem p

Answer: C

Explanation:
Explanation
When a user initiates a sensor install, the logs can be found in %SYSTEMROOT%\Temp. This folder contains temporary files and folders created by the system or applications, including the sensor installation logs. The sensor installation logs have names that start with CSFalconContainer and end with .log, such as CSFalconContainer-2023-08-31_11-23-21.log. These logs can help you troubleshoot any issues or errors that may occur during the sensor installation process3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 36
Custom IOA rules are defined using which syntax?

  • A. Glob
  • B. PowerShell
  • C. Yara
  • D. Regex

Answer: D

Explanation:
Explanation
Regex guidelines https://falcon.crowdstrike.com/documentation/68/detection-and-prevention-policies#regex


NEW QUESTION # 37
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?

  • A. Workflow Execution log
  • B. Workflow Audit log
  • C. Custom Alert History
  • D. Falcon UI Audit Trail

Answer: A


NEW QUESTION # 38
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?

  • A. \Program Files\My Program\My Files\*
  • B. \Program Files\My Program\*
  • C. *\*
  • D. *\Program Files\My Program\*\

Answer: A

Explanation:
Explanation
The exclusion pattern that will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe is \Program Files\My Program\My Files*. This pattern will match any file under the My Files folder, including program.exe, and exclude them from detections. The other patterns are either incorrect or too broad to prevent detections on this specific file. Reference: [CrowdStrike Falcon User Guide], page 37.


NEW QUESTION # 39
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?

  • A. Configure a Real Time Response policy allowlist with the specific IP addresses
  • B. Configure a Containment Policy with the entire internal IP CIDR block
  • C. Configure the Host firewall to allowlist the specific IP addresses
  • D. Configure a Containment Policy with the specific IP addresses

Answer: D

Explanation:
Explanation
While a host is Network contained, the administrator can allow the host to access internal network resources on specific IP addresses to perform patching and remediation by configuring a Containment Policy with the specific IP addresses. This policy allows users to specify which ports, protocols and IP addresses are allowed or blocked during network containment. The other options are either incorrect or not related to network containment. Reference: [CrowdStrike Falcon User Guide], page 40.


NEW QUESTION # 40
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?

  • A. Using IOC Management, add the hash of the binary in question and set the action to "Allow"
  • B. Using IOC Management, add the hash of the binary in question and set the action to "No Action"
  • C. Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"
  • D. Contact support and request that they modify the Machine Learning settings to no longer include this detection

Answer: A


NEW QUESTION # 41
On a Windows host, what is the best command to determine if the sensor is currently running?

  • A. ping falcon.crowdstrike.com
  • B. sc query csagent
  • C. netstat -a
  • D. This cannot be accomplished with a command

Answer: B

Explanation:
Explanation
On a Windows host, the best command to determine if the sensor is currently running is sc query csagent. This command will show the status of the csagent service, which is responsible for running the sensor on Windows systems. The output of this command will indicate if the service is running, stopped, or paused. If the service is running, the sensor is also running3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 42
On a Windows host, what is the best command to determine if the sensor is currently running?

  • A. ping falcon.crowdstrike.com
  • B. sc query csagent
  • C. netstat -a
  • D. This cannot be accomplished with a command

Answer: B


NEW QUESTION # 43
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?

  • A. Remediation Manager
  • B. Real Time Responder - Active Responder
  • C. Falcon Analyst - Read Only
  • D. Real Time Responder - Read Only Analyst

Answer: D

Explanation:
Explanation
The Real Time Responder - Read Only Analyst only allows to run the commands
"cat,cd,clear,env,eventlog,filehash,getsid,help,history,ipconfig,ls,mount,netstat,ps,reg" the role do not have permission to get files so it is the most aproximated profile for the requested capabilities.


NEW QUESTION # 44
Which of the following is TRUE of the Logon Activities Report?

  • A. It gives a detailed list of all logon activity for users
  • B. It only gives a summary of the last logon activity for users
  • C. The report can be filtered by computer name
  • D. Shows a graphical view of user logon activity and the hosts the user connected to

Answer: A


NEW QUESTION # 45
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?

  • A. Customer ID (CID)
  • B. Agent ID (AID)
  • C. Bulk update key
  • D. Maintenance token

Answer: D

Explanation:
Explanation
When uninstalling a sensor, a maintenance token is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies. This setting prevents unauthorized or accidental uninstallation of sensors by requiring a token that can be generated from the Falcon console. The other options are either incorrect or not related to uninstalling a sensor. Reference: CrowdStrike Falcon User Guide, page
29.


NEW QUESTION # 46
Which command would tell you if a Falcon Sensor was running on a Windows host?

  • A. sc.exe query falcon
  • B. netstat.exe -f
  • C. sc.exe query csagent
  • D. cswindiag.exe -status

Answer: C

Explanation:
Explanation
The command that would tell you if a Falcon Sensor was running on a Windows host is sc.exe query csagent.
This command will show the status of the csagent service, which is responsible for running the sensor on Windows systems. The output of this command will indicate if the service is running, stopped, or paused. If the service is running, the sensor is also running3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator


NEW QUESTION # 47
Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?

  • A. To bundle the Sensor and Prevention policies together into a deployment package
  • B. Sensor Update policies are OS dependent
  • C. This is false. One policy can be applied to all Operating Systems
  • D. To assist with auditing and change management

Answer: B

Explanation:
Explanation
Sensor Update policies need to be configured for each OS (Windows, Mac, Linux) because Sensor Update policies are OS dependent. A Sensor Update policy is a policy that controls how and when the Falcon sensor is updated on a host. Sensor Update policies are specific to each operating system type, as different operating systems have different sensor versions, features, and requirements. Therefore, you need to create and assign separate Sensor Update policies for each operating system type in your environment1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike


NEW QUESTION # 48
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?

  • A. Customer ID (CID)
  • B. Agent ID (AID)
  • C. Bulk update key
  • D. Maintenance token

Answer: D


NEW QUESTION # 49
What is the purpose of a containment policy?

  • A. To define the trigger under which a machine is put in Network Containment (e.g. a critical detection)
  • B. To define the duration of Network Containment
  • C. To define which Falcon analysts can contain endpoints
  • D. To define allowed IP addresses over which your hosts will communicate when contained

Answer: A


NEW QUESTION # 50
......

CrowdStrike Certified CCFA-200  Dumps Questions Valid CCFA-200 Materials: https://www.examcost.com/CCFA-200-practice-exam.html

Current CCFA-200 Exam Dumps [2024] Complete CrowdStrike Exam Smoothly: https://drive.google.com/open?id=1Xj5LM9uKiAJjlcYaRlVjIugMn6Nv8dv7