PAPER VERIFIED QUESTIONS AND
ANSWERS
◉ If your sensor requires more time to connect to the Crowdstrike cloud
duringinstallation, what parameter can you use? Answer: ProvNoWait=1
◉ Around what model are workflows built? Answer: Trigger, Condition,
Action
◉ Host groups are created in which module? Answer: Host Setup and
Managment
◉ Which of the following are availlable templates for Custom Alerts?
Answer: Analyst contained a host
Sensor entering RFM
Real Time Response session initiation
◉ How often is it recommended to update the host's sensors? Answer:
Monthly
◉ Select the statement which best describes the steps to create a policy
with detection Only and No prevention? Answer: You must set all
detection sliders to the desired detection level and all prevention sliders
to disabled. Do NOT activate any of the other blocking or malware
prevention options.
, ◉ Host must be connected to the Crowdstrike cloud in a secure manner,
what port is required for the communication? Answer: 443
◉ When setting up a user with the Real Time Responder - Read Only
Analyst (RTR Read Only Analyst) Role, what type of access will the
user have when connecting to a host? Answer: Can run a core set of
read-only response commands to perform reconnaissance.
◉ If you need to see who made changes to a prevention policy, which
report will be helpful. Answer: Prevention Policy Audit Trail
◉ After how many days, any sensor in your environment becomes
inactive? Answer: 180
◉ What is the available deployment method when deploying
CrowdStrike falcon sensors across multiple endpoints? Answer: Manual
Deployment? *Third Party Deployment, User Group Deployment and
Third-Party Software Deployment, Group Policy and Third-Party
Software Deployment)
◉ What type of traffic and port needs to be allowed between your
network and Crowdstrike's Cloud Network Addresses? Answer: TLS on
port 443
◉ What is the Machine-Learning Prevention Monitoring Report used
for? Answer: To view malware that would have been blocked in your