Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFA-200 Exam

Exam Name: CrowdStrike Certified Falcon Administrator
Exam Code: CCFA-200
Related Certification(s): CrowdStrike Certified Falcon Administrator CCFA Certification
Certification Provider: CrowdStrike
Number of CCFA-200 practice questions in our database: 153 (updated: May. 10, 2024)
Expected CCFA-200 Exam Topics, as suggested by CrowdStrike :
  • Topic 1: Create a new user, delete a user and edit a user, etc/ Describe the capabilities and limitations of each RTR role
  • Topic 2: Perform root cause analysis related to system/user issues/ Apply additional/advanced options for images/VDIs, tokens and tags
  • Topic 3: Resolve policy settings, permissions and threshold issues/ Apply basic sensor install requirements and installation processes
  • Topic 4: Determine which reports to use when reporting on information relating to a host/ Apply appropriate settings to successfully install a Falcon sensor on Windows, Linux and macOS
  • Topic 5: Explain what precedence does regarding prevention policies/ Determine roles required for access to features and functionality in the Falcon console
  • Topic 6: Explain what Machine Learning is "on sensor" vs. ?the cloud?/ Explain the impact of reduced functionality mode (RFM) and why it might be caused
  • Topic 7: Describe policy types, components, application and workflow/ Propose how filtering might be used in the Host Management page
  • Topic 8: Describe what precedence does regarding sensor update policies/ Create custom IOA rules to monitor behavior that is not fundamentally malicious
  • Topic 9: Explain the differences between the visibility and hunting reports/ Explain what information is in the Falcon UI Audit Trail Report
  • Topic 10: Configure custom alerts to notify individuals about policies, detections and incidents/ Recall how long inactive sensors are retained to define your data backup plan
  • Topic 11: Explain what information can be found in the visibility reports/ Explain where build versions are visible for a single sensor or across your environment
  • Topic 12: Allowlist network traffic so it can connect to contained hosts/ Explain the information shown in the remote logon activity report
  • Topic 13: Explain what information is contained in Machine-Learning Prevention Monitoring Report/ Explain the effect of disabling detections on a host
Disscuss CrowdStrike CCFA-200 Topics, Questions or Ask Anything Related

Currently there are no comments in this discussion, be the first to comment!

Free CrowdStrike CCFA-200 Exam Actual Questions

Note: Premium Questions for CCFA-200 were last updated On May. 10, 2024 (see below)

Question #1

You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?

Reveal Solution Hide Solution
Correct Answer: D

The option that is true when a Windows host is in Reduced Functionality Mode (RFM) is that some detection patterns and preventions will not be triggered. RFM is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. When a Windows sensor is in RFM, it will only provide basic prevention capabilities, such as blocking known malware hashes and preventing script execution from the %TEMP% directory. The sensor will not send any telemetry or detection events to the Falcon platform, and will not receive any policy or update changes from the Falcon cloud. This means that some detection patterns and preventions that rely on telemetry, machine learning, or cloud analysis will not be triggered.


Question #3

Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?

Reveal Solution Hide Solution
Question #4

You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?

Reveal Solution Hide Solution
Correct Answer: A

Turn on the Script-Based Execution Monitoring prevention policy setting to enable the 'Falcon sensor to monitor the contents of scripts and shells that are popular mechanisms for executing malicious code on hosts. This setting does not kill or block scripts.'

Scripting languages:

Excel 4.0 macros

JScript

VBA Macros

VBScript

The Sensor Visibility setting that should be turned on within the Prevention policy settings to monitor suspicious VBA macros is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. VBA (Visual Basic for Applications) is a scripting language that can be embedded in Microsoft Office documents, such as Word or Excel. VBA macros can be used to automate tasks or perform actions within the documents, but they can also be abused by attackers to deliver malware or execute malicious code. Script-based Execution Monitoring can help detect and prevent such attacks by monitoring the contents of VBA macros for execution of malicious content.



Unlock Premium CCFA-200 Exam Questions with Advanced Practice Test Features:
  • Select Question Types you want
  • Set your Desired Pass Percentage
  • Allocate Time (Hours : Minutes)
  • Create Multiple Practice tests with Limited Questions
  • Customer Support
Get Full Access Now

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77