CCFA-200b試験の準備方法|認定するCCFA-200b試験試験|素敵なCrowdStrike Falcon Administrator日本語対策献身と熱意を持ってCCFA-200bガイド資料を段階的に学習する場合、必死に試験に合格することを保証します。学習資料の権威あるプロバイダーとして、潜在顧客からより多くの注目を集めるために、常に同等のテストと比較してCCFA-200b模擬テストの高い合格率を追求しています。将来的には、CCFA-200b試験トレントは、高い合格率でより魅力的で素晴らしいものになると信じています。 CrowdStrike Falcon Administrator 認定 CCFA-200b 試験問題 (Q108-Q113):質問 # 108
What default user role can manage API credentials?
A. Falcon Security Lead
B. Endpoint Manager
C. Falcon API Manager
D. Falcon Administrator
正解:D
質問 # 109
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?
A. Configure a Containment Policy with the specific IP addresses
B. Configure a Containment Policy with the entire internal IP CIDR block
C. Configure the Host firewall to allowlist the specific IP addresses
D. Configure a Real Time Response policy allowlist with the specific IP addresses
正解:A
解説:
While a host is Network contained, the administrator can allow the host to access internal network resources on specific IP addresses to perform patching and remediation by configuring a Containment Policy with the specific IP addresses. This policy allows users to specify which ports, protocols and IP addresses are allowed or blocked during network containment. The other options are either incorrect or not related to network containment.
質問 # 110
You are creating a new host group that needs to contain all of the servers in your environment regardless of the installed operating system.
Which filter should be applied to the group's assignment rule to accomplish this task?
A. Manufacturer-All
B. Model - Server
C. Build - Server
D. Type - Server
正解:D
質問 # 111
Which statement is TRUE regarding disabling detections on a host?
A. Hosts with detections disabled will not alert on anything until detections are enabled again
B. Hosts with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
C. Hosts cannot have their detections disabled individually
D. Hosts with detections disabled will not alert on blocklisted hashes or machine learning detections, but will still alert on lOA-based detections. It will remain that way until detections are enabled again
正解:A
解説:
The statement that is true regarding disabling detections on a host is that hosts with detections disabled will not alert on anything until detections are enabled again. As explained in question
127, disabling detections for a host will stop the sensor from sending any detection or prevention events to the Falcon console, and remove any existing events for that host from the console. This means that the host will not alert on anything, including blocklisted hashes, machine learning detections, or indicator of attack (IOA)-based detections. The host will remain in this state until detections are enabled again.
質問 # 112
On which page of the Falcon console would you create sensor groups?
A. Host management
B. Sensor update policies
C. Host groups
D. User management
正解:C
解説:
The only place where create host groups is in " Host and setup management > host Groups> Create a group" In Sensor Update policies you can only asign a group of host to the policy not creating a group of hosts.