
[2025年最新] 最高の試験CCFA-200b問題集は無料サイトの資料を試そう
無料CrowdStrike Certified Falcon Administrator CCFA-200bオフィシャル認証ガイドPDFをダウンロード
質問 # 70
You have 100 hashes that have been prohibited by management and need to be blocked within your organization.
Using Falcon, what is the best way to accomplish this?
- A. Navigate to Configure > Prevention policies. Inside this dashboard, add an IOC Policy. Add the list of hashes as a CSV file. Set the action to "Block and Alert." Verify the option for Custom Blocking inside Execution Blocking is active.
- B. Navigate to Configure > IOC Management. Inside this dashboard, add a custom IOAdd the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.
- C. Navigate to Configure > Prevention policies. Inside this dashboard, add an IOC Policy. Add the list of hashes as CSV file. Set the action to "Block." Verify the option for Custom Execution Blocking is active.
- D. Navigate to Configure > IOC Management. Inside this dashboard, add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.
正解:B
質問 # 71
Which of the following is NOT an available action for an API Client?
- A. Retrieve an API Client Secret
- B. Delete an API Client
- C. Reset an API Client Secret
- D. Edit an API Client
正解:A
解説:
The option that is not an available action for an API Client is Retrieve an API Client Secret. An API Client is an entity that represents a user or application that can access the Falcon platform programmatically via the Falcon APIs. An API Client has an API Client ID and an API Client Secret, which are used for authenticating and authorizing API requests. You can create and manage API Clients in the API Clients and Keys page in the Falcon console. The available actions for an API Client are Edit an API Client, Reset an API Client Secret, and Delete an API Client. You cannot retrieve an API Client Secret after it has been created, as it is only displayed once during creation for security reasons.
質問 # 72
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
- A. IOA Exclusions
- B. IOC Exclusions
- C. Machine Learning Exclusions
- D. Sensor Visibility Exclusion
正解:A
解説:
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary.
質問 # 73
How does the Unique Hosts Connecting to Countries Map help an administrator?
- A. It helps visualize global network communication
- B. It displays intrusions from foreign countries
- C. It highlights countries with known malware
- D. It identifies connections containing threats
正解:A
解説:
The Unique Hosts Connecting to Countries Map helps an administrator to visualize global network communication. The map shows the number of unique hosts in your environment that have established network connections to different countries in the past 24 hours. You can use this map to identify unusual or suspicious network activity, such as connections to high-risk countries or regions, or connections from hosts that are not expected to communicate with external entities.
質問 # 74
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A. It is an auditing requirement
- B. To assist with testing and tracking sensor rollouts
- C. The network protocols are different for each host OS
- D. There may be special considerations for each OS
正解:D
質問 # 75
Which of the following best describes the Default Sensor Update policy?
- A. The Default Sensor Update policy is disabled by default
- B. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature
- C. The Default Sensor Update policy is a "catch-all" policy
- D. The Default Sensor Update policy is only used for testing sensor updates
正解:C
解説:
The Default Sensor Update policy is a "catch-all" policy. This means that any host that is not assigned to a specific sensor update policy will inherit the settings from the Default Sensor Update policy. The Default Sensor Update policy is enabled by default and has the "Uninstall and maintenance protection" feature turned on. You can modify the settings of the Default Sensor Update policy, but you cannot delete or disable it.
質問 # 76
How can a API client secret be viewed after it has been created?
- A. Selecting "show secret" within the 3-dot dropdown menu will reveal the secret for the selected api client
- B. The API client secret must be reset or a new client created as the secret cannot be viewed after it has been created
- C. Within the API management page, API client secrets can be accessed within the "edit client" functionality
- D. The API client secret can be provided by support via direct email request from a Falcon Administrator
正解:B
解説:
The way an API client secret can be viewed after it has been created is that the API client secret must be reset or a new client created as the secret cannot be viewed after it has been created.
As explained in question 137, an API client secret is only displayed once during creation for security reasons. If you lose or forget your API client secret, you cannot view it again in the Falcon console. You have two options to resolve this issue: either reset your API client secret or create a new API client. Resetting your API client secret will generate a new secret for your existing API client, which will invalidate any previous secret. Creating a new API client will generate a new API client ID and secret, which will require you to update any applications or scripts that use the Falcon APIs.
質問 # 77
Which of the following can a Falcon Administrator edit in an existing user's profile?
- A. Email address
- B. Working groups
- C. Phone number
- D. First or Last name
正解:D
解説:
Roles are never called 'working groups' in the documentation. The only other option that can be edited on a existing user is first and last name.
質問 # 78
You need to create a rule to block all process executions of Telegram in your environment.
Which custom IOA rule configuration would accomplish this?
- A. Custom IOA rule set to Monitor on an Image Filename of .*Telegram.*
- B. Custom IOA rule configuration cannot block non-malicious binaries from executing
- C. Custom IOA rule set to Block Execution on an Image Filename of .*Telegram.*
- D. Custom IOA rule set to Detect on an Image Filename of .*Telegram.*
正解:C
質問 # 79
You have created a new static host group to test a newly created sensor update policy, and need to add 500 servers into the group. You want to upload a list of hosts to Falcon for automatic addition into the group.
What file format must the list be for this to be successfully accomplished?
- A. TXT
- B. XLSX
- C. JSON
- D. PDF
正解:A
質問 # 80
How do you assign a Prevention policy to one or more hosts?
- A. Create a new policy and assign it directly to those hosts on the Host Management page
- B. Create a new policy and assign it directly to those hosts on the Prevention policy page
- C. Modify the users roles on the User Management page
- D. Ensure the hosts are in a group and assign that group to a custom Prevention policy
正解:D
解説:
The administrator can assign a Prevention policy to one or more hosts by ensuring the hosts are in a group and assigning that group to a custom Prevention policy. This allows users to apply different prevention settings and options to different groups of hosts based on their needs and preferences. The other options are either incorrect or not applicable to assigning a Prevention policy.
質問 # 81
A member of your SECOPS team currently has the role of Falcon Security Lead to be able to Manage detections, quarantine files and reset user credentials. Which additional role is required to also allow them to view and modify remediation actions?
- A. Remediation Manager
- B. Quarantine Manager
- C. Endpoint Manager
- D. Detections Exception Manager
正解:A
質問 # 82
When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?
- A. Trigger Details
- B. Filter
- C. Condition
- D. Option
正解:B
質問 # 83
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
- A. Real-time offline protection
- B. Next-Gen Antivirus (NGAV) protection
- C. Identification and analysis of unknown executables
- D. Adware and Potentially Unwanted Program detection and prevention
正解:C
解説:
According to documentation (documentation/detections/technique/sensor-based-ml-cst0007):
CrowdStrike sensor-based machine learning (ML) identifies and analyzes unknown executables as they run on hosts. This technique is triggered by files and file attributes associated with known malware. This is similar to the [Cloud- basedML](/support/documentation/detections/technique/cloud-based-ml) technique. Cloud-based ML is informed by global analysis of executables that classifies and identifies malware. The key difference is that it doesn't run on hosts when they're offline.
質問 # 84
In order to quarantine files on the host, what prevention policy settings must be enabled?
- A. Enable Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration
- B. Enable Malware Protection and Windows Anti-Malware Execution Blocking
- C. Enable Behavior-Based Threat Prevention sliders and Advanced Remediation Actions
- D. Enable Malware Protection and Custom Execution Blocking
正解:A
解説:
The option that will enable Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" is to enable Malware Protection and Windows Anti-Malware Execution Blocking. Malware Protection is a feature that enables the Next-Gen Antivirus Prevention sliders, which allow you to adjust the level of sensitivity and aggressiveness of the Falcon sensor's machine learning engine, which uses artificial intelligence to identify and stop unknown threats.
Windows Anti- Malware Execution Blocking is a feature that enables the "Quarantine & Security Center Registration" setting, which allows you to quarantine malicious files and register them in the Windows Security Center.
質問 # 85
On a Windows host, what is the best command to determine if the sensor is currently running?
- A. sc query csagent
- B. netstat -a
- C. This cannot be accomplished with a command
- D. ping falcon.crowdstrike.com
正解:A
解説:
On a Windows host, the best command to determine if the sensor is currently running is sc query csagent. This command will show the status of the csagent service, which is responsible for running the sensor on Windows systems. The output of this command will indicate if the service is running, stopped, or paused. If the service is running, the sensor is also running.
質問 # 86
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
- A. A host was offline for more than 24 hours
- B. A patch was pushed overnight to all Windows systems
- C. A Sensor Update Policy was misconfigured
- D. A host was placed in network containment from a detection
正解:B
解説:
The most likely culprit causing multiple Windows hosts to be in Reduced Functionality Mode (RFM) is a patch that was pushed overnight to all Windows systems. RFM occurs when the sensor detects a change in the operating system that requires a reboot to complete. A patch is one of the common causes of such a change. The other options are either incorrect or not related to RFM.
質問 # 87
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
- A. 0
- B. 1
- C. 2
- D. 3
正解:A
解説:
There are three "Auto" sensor version update options available for Windows Sensor Update Policies:
Auto - N-1, Auto - TEST-QA and Auto - Latest. These options allow the administrator to automatically update the sensor version to the previous stable version, the latest test version or the latest stable version, respectively.
質問 # 88
Which command would tell you if a Falcon Sensor was running on a Windows host?
- A. netstat.exe -f
- B. cswindiag.exe -status
- C. sc.exe query csagent
- D. sc.exe query falcon
正解:C
解説:
The command that would tell you if a Falcon Sensor was running on a Windows host is sc.exe query csagent. This command will show the status of the csagent service, which is responsible for running the sensor on Windows systems. The output of this command will indicate if the service is running, stopped, or paused. If the service is running, the sensor is also running.
質問 # 89
......
CrowdStrike CCFA-200bオフィシャル認証ガイドPDF:https://www.goshiken.com/CrowdStrike/CCFA-200b-mondaishu.html
試験CCFA-200bのCrowdStrike Falcon Administratorの問題集にはここにある:https://drive.google.com/open?id=1F4NpXn_k1IL52jsdmx-ESJ3OFczlrud5