CrowdStrike Certified Falcon Administrator CCFA-200 Exam Practice Test

Page: 1 / 14
Total 153 questions
Question 1

What are custom alerts based on?



Answer : C

Scheduling a Custom Alert for your environment consists of three steps: choosing the template you'd like to configure, previewing the search results, then scheduling the alert. Use Custom Alerts to configure email alerts using predefined templates so you're notified about specific activity in your environment. When an alert runs and finds results, it sends an email to specified recipients instead of generating a new detection. Custom Alerts let you set up email alerts based on predefined templates that cover a wide range of topics including Real Time Response session initiation, host containment, OS security settings, and more that are not yet covered by notification workflows.


Question 2

Once an exclusion is saved, what can be edited in the future?



Question 3

After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?



Question 4

How do you find a list of inactive sensors?



Question 5
Question 6
Question 7

Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?



Answer : A

The exclusion pattern that will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe is \Program Files\My Program\My Files*. This pattern will match any file under the My Files folder, including program.exe, and exclude them from detections. The other patterns are either incorrect or too broad to prevent detections on this specific file. Reference: [CrowdStrike Falcon User Guide], page 37.


Page:    1 / 14   
Total 153 questions