Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CrowdStrike Falcon Certification Program CCFA-200b Reddit Questions

Page: 3 / 8
Total 100 questions

CrowdStrike Falcon Certification Program Questions and Answers

Question 9

What is the recommended approach for managing host groups over time?

Options:

A.

Create separate groups for each department

B.

Create groups based on IP ranges

C.

Maintain multiple overlapping host groups

D.

Minimize the number of groups

Question 10

How are prevention policies assigned to hosts in the Falcon platform?

Options:

A.

Through host group membership

B.

Through direct host assignment

C.

Through IP address ranges

D.

Through manual configuration

Question 11

Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?

Options:

A.

Write an IOA rule to monitor process creation of .*\\remote\.exe

B.

Create an exclusion for remote.exe and set a workflow to email you every time the exclusion is used

C.

Write a scheduled search looking for ProcessRollup2 events for remote.exe

D.

Write an IOC for remote.exe

Question 12

To improve the organization’s security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a new workflow from scratch, what component of the workflow must be configured first?

Options:

A.

Action

B.

Trigger

C.

Condition

D.

Workflow Name

Page: 3 / 8
Total 100 questions