Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CrowdStrike Falcon Certification Program Changed CCFA-200b Questions

Page: 4 / 8
Total 100 questions

CrowdStrike Falcon Certification Program Questions and Answers

Question 13

When would the No Action option be assigned to a hash in IOC Management?

Options:

A.

When you want to save the indicator for later action, but do not want to block or allow it at this time

B.

There is no such option as No Action available in the Falcon console

C.

When you want to add the indicator to your allowlist, but not detect it

D.

When you want to add the indicator to your blocklist and show it as a detection

Question 14

Which default user role will allow you to see all analyst session details?

Options:

A.

Falcon Security Lead

B.

Real Time Response - Read-Only Analyst

C.

Falcon Administrator

D.

Real Time Response - Administrator

Question 15

Why would you add IP addresses to a containment policy?

Options:

A.

You want to automate the Network Containment process based on the IP address of a host

B.

A new group of analysts need to be able to place hosts under Network Containment

C.

Your organization has resources that need to be accessible when hosts are network contained

D.

Your organization has additional IP addresses that need to be able to access the Falcon console

Question 16

What is true about User Accounts created by the Falcon Administrator?

Options:

A.

By default, all User Accounts are created with the Falcon Analyst role

B.

All new User Accounts are created using an employee identification number

C.

All User Accounts must start with the domain identifier and number

D.

All User Accounts must be created with an email address from the list of approved domains

Page: 4 / 8
Total 100 questions