CCFA-200b CrowdStrike Falcon Certification Program Questions and Answers
A member of your SECOPS team is building custom scripts for RTR, but they are unable to save or share them in Falcon. What additional role do they need?
What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?
A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?
Where can you find the history of the successes and failures for any Fusion SOAR workflows?
After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?
In order to quarantine files on the host, what prevention policy settings must be enabled?
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?
To improve the organization’s security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a new workflow from scratch, what component of the workflow must be configured first?
Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?
A Falcon Administrator is unable to initiate a Real-Time Response (RTR) session. What is the most likely cause?
During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?
Which report would show you an overview of the top ten most-applied policies by sensors in your environment?
When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?
You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that it executes successfully?
To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group. What is required to safely and successfully test your new sensor update policy on only your test Windows servers?
When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?
Your leadership wants controls in place for immediate action on any OverWatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?