Leads4pass > CrowdStrike > CrowdStrike Falcon Certification Program > CCFA-200 > CCFA-200 Online Practice Questions and Answers

CCFA-200 Online Practice Questions and Answers

Questions 4

The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?

A. SSL inspection should be configured to occur on all Falcon traffic

B. Some network configurations, such as deep packet inspection, interfere with certificate validation

C. HTTPS interception should be enabled to proceed with certificate validation

D. Common sources of interference with certificate pinning include protocol race conditions and resource contention

Buy Now
Questions 5

Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?

A. .*badguydomain.com.*

B. \Device\HarddiskVolume2\*.exe -SingleArgument www.badguydomain.com /kill

C. badguydomain\.com.*

D. Custom IOA rules cannot be created for domains

Buy Now
Questions 6

How does the Unique Hosts Connecting to Countries Map help an administrator?

A. It highlights countries with known malware

B. It helps visualize global network communication

C. It identifies connections containing threats

D. It displays intrusions from foreign countries

Buy Now
Questions 7

What is the purpose of the Machine-Learning Prevention Monitoring Report?

A. It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

B. It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

C. It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

D. It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings

Buy Now
Questions 8

What is the maximum number of patterns that can be added when creating a new exclusion?

A. 10

B. 0

C. 1

D. 5

Buy Now
Questions 9

When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?

A. Username

B. Model

C. Domain

D. Hostname

Buy Now
Questions 10

Which of the following is TRUE regarding disabling detections for a host?

A. After disabling detections, the host will operate in Reduced Functionality Mode (RFM) until detections are enabled

B. After disabling detections, the data for all existing detections prior to disabling detections is removed from the Event Search

C. The DetectionSummaryEvent continues being sent to the Streaming API for that host

D. The detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled

Buy Now
Questions 11

Under the "Next-Gen Antivirus: Cloud Machine Learning" setting there are two categories, one of them is "Cloud Anti-Malware" and the other is:

A. Adware and PUP

B. Advanced Machine Learning

C. Sensor Anti-Malware

D. Execution Blocking

Buy Now
Questions 12

Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?

A. Use the Sensor Report to filter to the specific endpoint

B. Use the Investigate > Host Search to filter to the specific endpoint

C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details

D. From a command line, run the sc query csagent -version command

Buy Now
Questions 13

What information does the API Audit Trail Report provide?

A. A list of analyst login activity

B. A list of specific changes to prevention policy

C. A list of actions taken via Falcon OAuth2-based APIs

D. A list of newly added hosts

Buy Now
Exam Code: CCFA-200
Exam Name: CrowdStrike Certified Falcon Administrator
Last Update: Dec 16, 2024
Questions: 152
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99