Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CCFA-200b Exam Results

Page: 7 / 8
Total 100 questions

CrowdStrike Falcon Certification Program Questions and Answers

Question 25

Excluding mobile devices, what kind of hosts can be contained in Falcon?

Options:

A.

Windows and MacOS hosts running the Falcon sensor

B.

Windows and Linux hosts running the Falcon sensor

C.

Windows, Linux, and container hosts running the Falcon sensor

D.

Windows, Linux, and MacOS hosts running the Falcon sensor

Question 26

Your leadership wants controls in place for immediate action on any Overwatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?

Options:

A.

Create a Fusion SOAR workflow to contain the host and email the Overwatch team

B.

Create a Fusion SOAR workflow to create a detection for Overwatch and email the SOC team

C.

Create a Fusion SOAR workflow to trigger on an Overwatch detection and set it to block the detection

D.

Create a Fusion SOAR workflow using the Overwatch playbook to contain the host and email the SOC team

Question 27

What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?

Options:

A.

Hosts Overview

B.

Sensor Health

C.

Activity Overview

D.

Support and resources

Question 28

A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

B.

Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools

C.

Remove Host containment and update the host with all patches

D.

Create a Firewall Policy that allow lists your patch management tools

Page: 7 / 8
Total 100 questions