Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CrowdStrike: CCFA

Rating
-
Sold
-
Pages
46
Grade
A+
Uploaded on
07-09-2024
Written in
2024/2025

Falcon Console Guest - answer-User MGN: - View Documentation and your own user profile. - View Support Portal User MGN: Falcon Administrator - answer-User MGN: - Access all functionality in the console with the exception of some RTR functionality. Workflow Author - answer-User MGN: - Create and edit workflows. - Re-execute failed workflows. - This role requires at least one other role to be able to access the falcon console. - Cannot include RTR actions unless also assigned the RTR Administrator Role. Dashboard Admin - answer-User MGN: - Create, edit, manage and delete dashboards. - This role requires at least one other role to be able to access the falcon console. Prevention Policy Manager - answer-User MGN: - Create, edit and delete prevention policies. - This role can also view dashboards, host management, detections, file exclusions & sensor update policy. Desktop Support Analyst - answer-User MGN: - Install sensor, troubleshoot, view manuals. - Access docs about products functions and restrictions. Help Desk Analyst - answer-User MGN: - View Detections, host management, installation tokens, prevention policies, file exclusions, sensor update policies & dashboards. PREVENT ROLES: Falcon Administrator - answer-PREVENT ROLES: - Access all functionality in console with exception of some RTR functionality and custom IOAs. PREVENT ROLES: Falcon Security Lead - answer-PREVENT ROLES: - Manage detections, manage quarantined files, contain hosts, view exclusions. - Search for events, reset user credentials & 2FA. - View data about assets, accounts and applications in Discover. PREVENT ROLES: Falcon Analyst - answer-PREVENT ROLES: - Manage detections and quarantined files. - View Exclusions and Host Management. - View Firewall Rules, rule groups, policies and audit logs. PREVENT ROLES: Falcon Analyst - Read Only - answer-PREVENT ROLES: - View detections and exclusions and search events. - View all Identity Protection info. - View firewall rules, rule groups, policies and audit logs. PREVENT ROLES: Quarantine Manager - answer-PREVENT ROLES: - View, release and manage quarantined files. PREVENT ROLES: Endpoint Manager - answer-PREVENT ROLES: - Manage sensor deployment and maintain sensor configuration and update policies. - Create, edit and delete host groups and firewall rules. PREVENT ROLES: Detections Exceptions Manager - answer-PREVENT ROLES: - Add, edit and manage custom IOCs, ML Exclusions, IOA Exclusions and Sensor Visibility Exclusions. PREVENT ROLES: Remediation Manager - answer-PREVENT ROLES: - View and manage remediation actions taken by the Falcon console. Capabilities and Limitations: RTR READ ONLY ANALYST - answer-Capabilities and Limitations: + Can run a core set of read-only response commands to perform reconnaissance. - Cannot extract files, modify the device, or run certain scripts. - No access to "Edit and RunScript" tab. Capabilities and Limitations: RTR ACTIVE RESPONDER - answer-Capabilities and Limitations: + More access than RTR Read Only Analyst. + Can extract files using get command, can run commands that modify the device and run certain custom scripts. - Cannot create custom scripts, cannot upload files to hosts using put command and cannot directly run executables using the run command. - No access to "Edit and RunScript" tab. Capabilities and Limitations: RTR ADMINISTRATOR - answer-Capabilities and Limitations: + Can do everything the RESPONDER can do. + Plus create custom scripts, upload files to hosts using put, and directly run executables using run. + There are no limitations to this role. Create, edit, delete a new user: How do you Add a user? (How do you traverse through the UI to add a user) - answer-* ADMINISTRATIVE role for your Falcon subscription, such as FALCON ADMINISTRATOR is required * - Host setup and management Falcon users User management. - Click Add User in the upper right of the window. - Enter users email address, first name, last name. - Select one or more roles. - Click Add User Create, edit, delete a new user: How do you add a Delete? (How do you traverse through the UI to Delete a user) - answer-* ADMINISTRATIVE role for your Falcon subscription, such as FALCON ADMINISTRATOR is required * - Host setup and management Falcon users User management. - Find the desired user. - Click three-dot menu. - Select Delete User. - At confirmation, select Delete. You can also delete a user from the three-dot menu inside the User details. Create, edit, delete a new user: How do you Edit a user? (How do you traverse through the UI to Edit a user) - answer-- Edit username - Edit Roles - Reset 2FA - Reset Password A Falcon Administrator can make all changes to a user. A Falcon Security Lead can reset 2FA and password but cannot change the user or assign roles. Single Sign On - answer-If SSO isn't enabled in your environment, CrowdStrike sends an automated email to the user, prompting them to create a Falcon password and configure 2FA. If SSO is enabled, CrowdStrike doesn't send an automated email to the user. If you're planning to enable single sign-on (SSO), the email address must match the information in your Identity Provider. SENSOR DEPLOYMENT (Windows OS) Required Services installed and running - answer-Sensor Deployment: - LM Hosts - Network Store Interface (NSI) - Windows Base Filtering Engine (BFE) - Windows Power Services (Power) * LMHosts may be disabled if TCP/IP NetBios Helper is disabled* SENSOR DEPLOYMENT (Windows OS): using a proxy - Requirements using Web Proxy Automatic Discover (WPAD) - Requirements - answer-SENSOR DEPLOYMENT: - WinHTTP AutoProxy must be running. - DHCP Client must be running. SENSOR DEPLOYMENT (Windows OS): Registry Key Configuration - answer-SENSOR DEPLOYMENT: - HKEY_LOCAL_MACHINESYSTEMCurrentControlSetservicesDnscachetype - Value must be '0x' *This is the defaulted Microsoft setting for this key. - answer-SENSOR DEPLOYMENT (Windows OS) SENSOR DEPLOYMENT (Windows OS): Log File Location - answer-SENSOR DEPLOYMENT: %LOCALAPPDATA%temp SENSOR DEPLOYMENT (Windows OS): Networking Protocols - answer-SENSOR DEPLOYMENT: Falcon on commercial cloud: - TLS 1.0 or later Falcon on GovCloud: - TLS 1.1 or later *CrowdStrike cloud DOES NOT support connecting via SSL. Falcon uses TLS 1.2 on Win7 and WinServer 2008 R2 to communicate with the CrowdStrike cloud. If TLS 1.2 has been disabled, Falcon will negotiate TLS 1.1 or TLS 1.0 Falcon Commercial customers in US-1, US-2, EU-1 must have TLS 1.2 support enabled in Operating Systems, Web Browsers and HTTP Clients to prevent interruption of service and protection. SENSOR DEPLOYMENT (MAC OS): Requirements - answer-SENSOR DEPLOYMENT: Must have elevated privileges to install the sensor. No other services required. SENSOR DEPLOYMENT (Linux OS): Requirements - answer-SENSOR DEPLOYMENT: To determine Linux Kernel Information: uname -r Use the relevant support documentation for the kernel version installed. If installed on a kernel version not shown in the documentation, it WILL install, but will run in a REDUCED FUNCTIONALITY MODE (RFM). Sensor will continue to run in this mode until the sensor is updated to support the kernel version. Linux RFM only sends heartbeats. Nothing else. SENSOR DEPLOYMENT: NETWORKING REQUIREMENTS ALL OS - answer-'Requires TLS 1.2' Sensor needs to be able to connect to the CrowdStrike cloud during install. If connection cannot be established during install, it will attempt again 'after 10 minutes'. If it fails again, the sensor will 'uninstall from the system'. May need to AllowList TLS traffic from the following URLs: US-1: US-2: Falcon for GovCloud: EU Cloud: If the network requires allowlisting by IP address rather than Fully Qualified Domain Name (FQDN): Some network configurations that use Deep Packet Inspection can interfere with certificate validation. - Disable Deep Packet Inspection - Sometimes known as HTTPS Interception / TLS Interception / SSL Inspection - Common sources of this issue are anti-virus, firewalls and proxies. For Hosts using Proxies: - WinHTTP AutoProxy - DHCP Client (if using Web Proxy Automatic Discovery WPAD through DHCP) SENSOR DEPLOYMENT: (MOBILE) Requirements - answer-SENSOR DEPLOYMENT: Android 9+ IOS 13+ (Latest version) PREVENTION POLICIES: Location in UI (How to traverse to location) - answer-Endpoint Security Configuration Prevention Policies Hosts will always inherit the default Prevention policy - unless it has been assigned another policy. PREVENTION POLICIES: New Customers - Phase - answer-PREVENTION POLICIES: - A phased approach to Prevention policy implementation is recommended. - Windows & Mac (3 phases) / Linux (2 phases) - All systems are different however and this is not set in stone. PREVENTION POLICIES: PHASE 1 - answer-PREVENTION POLICIES: - Initial policy suitable for a rapid-deployment scenario along side a pre-existing Anti-Virus and/or HIPS suite. - Run for the absolute minimum time. - Identification of false positives and perform allow listing. - Detection only policy is typical. PREVENTION POLICIES: PHASE 2 - answer-PREVENTION POLICIES: - An interim policy offering solid protection. - Increase the ML detections and preventions. - Identification of further false positives and perform allow listing. PREVENTION POLICIES: PHASE 3 - answer-PREVENTION POLICIES: - Where you need to end up. - Recommended for all OS: 'Detections = Aggressive. Preventions = Moderate+' SENSOR UPDATE POLICIES - answer-Host setup and Management Deploy Sensor Update Policies Hosts will inherit the default Sensor Update Policy unless they've been assigned to a different Update Policy. Sensor update policy can control updates for hosts. Hosts can either update to the latest versions, be assigned a specific version or have updates disabled. *You can revert a sensor to a previous version but only a version released in the last '180 days'. 180-day support window, therefore strongly recommend to test and update to the latest sensor version ASAP. Install Falcon on Windows: Install Requirements - answer-Install Falcon on * Host Setup and Management Sensor Downloads - Download Sensor install file - Customer ID Checksum Install Falcon on Windows: USING THE GUI - answer-Install Falcon on * Launch the sensor installer Enter CID Accept EULA Follow Instructions Install Falcon on Windows: USING COM

Show more Read less
Institution
CrowdStrike: CCFA
Course
CrowdStrike: CCFA

Content preview

CrowdStrike: CCFA questions and answers
Falcon Console Guest - answer-User MGN:
- View Documentation and your own user profile.
- View Support Portal

User MGN: Falcon Administrator - answer-User MGN:
- Access all functionality in the console with the exception of some RTR functionality.

Workflow Author - answer-User MGN:
- Create and edit workflows.
- Re-execute failed workflows.
- This role requires at least one other role to be able to access the falcon console.
- Cannot include RTR actions unless also assigned the RTR Administrator Role.

Dashboard Admin - answer-User MGN:
- Create, edit, manage and delete dashboards.
- This role requires at least one other role to be able to access the falcon console.

Prevention Policy Manager - answer-User MGN:
- Create, edit and delete prevention policies.
- This role can also view dashboards, host management, detections, file exclusions &
sensor update policy.

Desktop Support Analyst - answer-User MGN:
- Install sensor, troubleshoot, view manuals.
- Access docs about products functions and restrictions.

Help Desk Analyst - answer-User MGN:
- View Detections, host management, installation tokens, prevention policies, file
exclusions, sensor update policies & dashboards.

PREVENT ROLES: Falcon Administrator - answer-PREVENT ROLES:
- Access all functionality in console with exception of some RTR functionality and custom
IOAs.

PREVENT ROLES: Falcon Security Lead - answer-PREVENT ROLES:
- Manage detections, manage quarantined files, contain hosts, view exclusions.
- Search for events, reset user credentials & 2FA.
- View data about assets, accounts and applications in Discover.

PREVENT ROLES: Falcon Analyst - answer-PREVENT ROLES:
- Manage detections and quarantined files.
- View Exclusions and Host Management.
- View Firewall Rules, rule groups, policies and audit logs.

,PREVENT ROLES: Falcon Analyst - Read Only - answer-PREVENT ROLES:
- View detections and exclusions and search events.
- View all Identity Protection info.
- View firewall rules, rule groups, policies and audit logs.

PREVENT ROLES: Quarantine Manager - answer-PREVENT ROLES:
- View, release and manage quarantined files.

PREVENT ROLES: Endpoint Manager - answer-PREVENT ROLES:
- Manage sensor deployment and maintain sensor configuration and update policies.
- Create, edit and delete host groups and firewall rules.

PREVENT ROLES: Detections Exceptions Manager - answer-PREVENT ROLES:
- Add, edit and manage custom IOCs, ML Exclusions, IOA Exclusions and Sensor Visibility
Exclusions.

PREVENT ROLES: Remediation Manager - answer-PREVENT ROLES:
- View and manage remediation actions taken by the Falcon console.

Capabilities and Limitations: RTR READ ONLY ANALYST - answer-Capabilities and
Limitations:
+ Can run a core set of read-only response commands to perform reconnaissance.
- Cannot extract files, modify the device, or run certain scripts.
- No access to "Edit and RunScript" tab.

Capabilities and Limitations: RTR ACTIVE RESPONDER - answer-Capabilities and
Limitations:
+ More access than RTR Read Only Analyst.
+ Can extract files using get command, can run commands that modify the device and
run certain custom scripts.
- Cannot create custom scripts, cannot upload files to hosts using put command and
cannot directly run executables using the run command.
- No access to "Edit and RunScript" tab.

Capabilities and Limitations: RTR ADMINISTRATOR - answer-Capabilities and Limitations:
+ Can do everything the RESPONDER can do.
+ Plus create custom scripts, upload files to hosts using put, and directly run
executables using run.
+ There are no limitations to this role.

Create, edit, delete a new user:

How do you Add a user? (How do you traverse through the UI to add a user) - answer-*
ADMINISTRATIVE role for your Falcon subscription, such as FALCON ADMINISTRATOR is
required *

- Host setup and management > Falcon users > User management.
- Click Add User in the upper right of the window.
- Enter users email address, first name, last name.

,- Select one or more roles.
- Click Add User

Create, edit, delete a new user:

How do you add a Delete? (How do you traverse through the UI to Delete a user) -
answer-* ADMINISTRATIVE role for your Falcon subscription, such as FALCON
ADMINISTRATOR is required *

- Host setup and management > Falcon users > User management.
- Find the desired user.
- Click three-dot menu.
- Select Delete User.
- At confirmation, select Delete.

You can also delete a user from the three-dot menu inside the User details.

Create, edit, delete a new user:

How do you Edit a user? (How do you traverse through the UI to Edit a user) - answer--
Edit username
- Edit Roles
- Reset 2FA
- Reset Password

A Falcon Administrator can make all changes to a user.
A Falcon Security Lead can reset 2FA and password but cannot change the user or assign
roles.

Single Sign On - answer-If SSO isn't enabled in your environment, CrowdStrike sends an
automated email to the user, prompting them to create a Falcon password and configure
2FA. If SSO is enabled, CrowdStrike doesn't send an automated email to the user.

If you're planning to enable single sign-on (SSO), the email address must match the
information in your Identity Provider.

SENSOR DEPLOYMENT (Windows OS)

Required Services installed and running - answer-Sensor Deployment:

- LM Hosts
- Network Store Interface (NSI)
- Windows Base Filtering Engine (BFE)
- Windows Power Services (Power)
* LMHosts may be disabled if TCP/IP NetBios Helper is disabled*

SENSOR DEPLOYMENT (Windows OS):

using a proxy - Requirements

, using Web Proxy Automatic Discover (WPAD) - Requirements - answer-SENSOR
DEPLOYMENT:

- WinHTTP AutoProxy must be running.

- DHCP Client must be running.

SENSOR DEPLOYMENT (Windows OS):

Registry Key Configuration - answer-SENSOR DEPLOYMENT:

- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\type
- Value must be '0x00000020'

*This is the defaulted Microsoft setting for this key.

- answer-SENSOR DEPLOYMENT (Windows OS)

SENSOR DEPLOYMENT (Windows OS):

Log File Location - answer-SENSOR DEPLOYMENT:

%LOCALAPPDATA%\temp\

SENSOR DEPLOYMENT (Windows OS):

Networking Protocols - answer-SENSOR DEPLOYMENT:

Falcon on commercial cloud:

- TLS 1.0 or later

Falcon on GovCloud:

- TLS 1.1 or later

*CrowdStrike cloud DOES NOT support connecting via SSL.

Falcon uses TLS 1.2 on Win7 and WinServer 2008 R2 to communicate with the
CrowdStrike cloud.
If TLS 1.2 has been disabled, Falcon will negotiate TLS 1.1 or TLS 1.0

Falcon Commercial customers in US-1, US-2, EU-1 must have TLS 1.2 support enabled in
Operating Systems, Web Browsers and HTTP Clients to prevent interruption of service
and protection.

SENSOR DEPLOYMENT (MAC OS):

Written for

Institution
CrowdStrike: CCFA
Course
CrowdStrike: CCFA

Document information

Uploaded on
September 7, 2024
Number of pages
46
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$13.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TOPDOCTOR Abacus College, Oxford
Follow You need to be logged in order to follow users or courses
Sold
10
Member since
2 year
Number of followers
5
Documents
3395
Last sold
8 months ago
TOPGRADER!!

Looking for relevant and updated study material to help you ace your exams? TOPTIERGRADES has your back!!! I have essential exams, test-banks, study bites, assignments all graded A+, Have Complete solutions, and are updated regularly. Please feel free to message me if you are looking for a specific test bank that is not listed on my profile or want a test bank or exam sent to you directly as google doc link. In the event that any of the materials have an issue, please let me know and I\'ll do my best to resolve it or provide an alternative. Thank You & All The Very BEST!!!!!

Read more Read less
5.0

1 reviews

5
1
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions