CrowdStrike
CCFA-200b
Q1:
What must an admin do to reset a user's password?
○
A
From User Management, open the account details for the affected user and select 'Generate New Password'○
B
From User Management, select 'Reset Password' from the three dot menu for the affected user account○
C
From User Management, select 'Update Account' and manually create a new password for the affected user account○
D
From User Management, the administrator must rebuild the account as the certificate for user specific private/public key generation is no longer valid
CrowdStrike
CCFA-200b
Q2:
Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?
○
A
To bundle the Sensor and Prevention policies together into a deployment package○
B
Sensor Update policies are OS dependent○
C
To assist with auditing and change management○
D
This is false. One policy can be applied to all Operating Systems
CrowdStrike
CCFA-200b
Q3:
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?
○
A
Remediation Manager○
B
Real Time Responder -- Read Only Analyst○
C
Falcon Analyst -- Read Only○
D
Real Time Responder -- Active Responder
CrowdStrike
CCFA-200b
Q4:
What is the primary purpose of using glob syntax in an exclusion?
○
A
To specify a Domain be excluded from detections○
B
To specify exclusion patterns to easily exclude files and folders and extensions from detections○
C
To specify exclusion patterns to easily add files and folders and extensions to be prevented○
D
To specify a network share be excluded from detections
CrowdStrike
CCFA-200b
Q5:
Why is it important to know your company's event data retention limits in the Falcon platform?
○
A
This is not necessary; you simply select 'All Time' in your query to search all data○
B
You will not be able to search event data into the past beyond your retention period○
C
Data such as process records are kept for a shorter time than event data○
D
Your query will require you to specify the data pool associated with the date you wish to search