Q: 1
Which role should be assigned to a user who needs to monitor detections and run reports but should not
have access to modify configurations?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
As a CrowdStrike administrator, you have been tasked with creating a custom Indicator of Attack (IOA)
rule to monitor for the execution of a specific script file that is not inherently malicious but could be used
maliciously under certain circumstances. Which of the following configurations would be most
appropriate for this use case?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
You are configuring a prevention policy in CrowdStrike Falcon for endpoints in a highly secure
environment. Which of the following settings is the most appropriate to block unknown executables while
minimizing false positives?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
When creating a Host Group for all Workstations in an environment, what is the best method to ensure all
workstation hosts are added to the group?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however,
when applying the new prevention policy this group is not appearing in the list of available groups. What
is the most likely issue?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Your organization uses CrowdStrike Falcon and needs to minimize the risk of update-related downtime
during business hours. You are tasked with configuring the sensor update policy to control the timing of
update rollouts. Which setting will best allow you to control when updates are applied?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the
installation fails after 20 minutes. Which of the following parameters can be used to override the 20-
minute default provisioning window?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
What is the most effective way to identify hosts in the “Reduced Functionality Mode” (RFM) within the
CrowdStrike Falcon Console?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
You are a CrowdStrike Falcon administrator tasked with creating a dashboard that tracks endpoint
security across your organization. You want to add widgets to display real-time data on detections,
managed hosts, and policy compliance. Which of the following statements about customizing dashboards
in CrowdStrike Falcon is correct?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2