
あなたを合格させるCrowdStrike Certified Falcon Administrator CCFA-200日本語試験問題集で2025年06月21日には152問あります
CCFA-200日本語無料試験学習ガイド!(更新された152問あります)
質問 # 18
可視性レポートの Logan アクティビティにはどのような情報が提供されますか?
- A. ユーザーが最後にログインしたエンドポイントのリスト
- B. すべてのユーザーのすべてのログオンのリスト
- C. ローカル IP とローカル ポートに基づいてデバイスにリモート ログオンしているユーザーのリスト
- D. 国に基づいてデバイスにリモートログオンしている一意のユーザーのリスト
正解:A
解説:
The Logon Activities report under Visibility Reports provides a list of last endpoints that a user logged in to.
This report shows the user name, domain name, logon type, logon time and endpoint name for each logon event. The other options are either incorrect or not related to the report. Reference: [CrowdStrike Falcon User Guide], page 50.
質問 # 19
ホストの設定と管理 > ホスト管理ページ内のフィルターはどれですか?
- A. ユーザー名
- B. 地域
- C. BIOS バージョン
- D. または
正解:D
解説:
OU (organizational unit) is a filter within the Host setup and management > Host management page. The Host management page allows you to view and manage all the hosts in your environment that have Falcon sensors installed. You can filter the hosts by hostname, group, OS version, sensor version, last seen date, health events, detections, and preventions. You can also filter by OU, which is a logical grouping of hosts based on their Active Directory domain structure1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 20
次のオプションのうち、センサーベースの機械学習 (ML) にのみ備わっている機能はどれですか?
- A. 未知の実行ファイルの識別と分析
- B. 次世代アンチウイルス (NGAV) 保護
- C. アドウェアおよび潜在的に不審なプログラムの検出と防止
- D. リアルタイムオフライン保護
正解:A
解説:
According to documentation (documentation/detections/technique/sensor-based-ml-cst0007): CrowdStrike sensor-based machine learning (ML) identifies and analyzes unknown executables as they run on hosts. This technique is triggered by files and file attributes associated with known malware. This is similar to the
[Cloud-based ML](/support/documentation/detections/technique/cloud-based-ml) technique. Cloud-based ML is informed by global analysis of executables that classifies and identifies malware. The key difference is that it doesn't run on hosts when they're offline.
質問 # 21
CISO は、すべての Falcon アナリストに、侵害されたホスト上のファイルとファイル内容をローカルで表示する権限も付与する必要があるが、ホストからファイルを取り出す権限は付与しないことを決定しました。この要件を満たすために追加できる最も適切な役割は何ですか?
- A. ファルコンアナリスト - 読み取り専用
- B. リアルタイム レスポンダー - 読み取り専用アナリスト
- C. 修復マネージャー
- D. リアルタイム レスポンダー - アクティブ レスポンダー
正解:B
解説:
The Real Time Responder - Read Only Analyst only allows to run the commands
"cat,cd,clear,env,eventlog,filehash,getsid,help,history,ipconfig,ls,mount,netstat,ps,reg" the role do not have permission to get files so it is the most aproximated profile for the requested capabilities.
質問 # 22
ログオン アクティビティ レポートに関して正しいのは次のうちどれですか。
- A. ユーザーのすべてのログオンアクティビティの詳細なリストを表示します。
- B. レポートはコンピュータ名でフィルタリングできます
- C. ユーザーのログオンアクティビティとユーザーが接続したホストのグラフィカルビューを表示します。
- D. ユーザーの最後のログオンアクティビティの概要のみを表示します
正解:D
解説:
The Logon Activities Report shows a graphical view of user logon activity and the hosts the user connected to, but it only gives a summary of the last logon activity for users. It does not give a detailed list of all logon activity for users, nor can it be filtered by computer name. The other options are either incorrect or not true of the report. Reference: CrowdStrike Falcon User Guide, page 50.
質問 # 23
環境内のすべてのワークステーションのホスト グループを作成する場合、すべてのワークステーション ホストがグループに追加されるようにするための最適な方法は何ですか?
- A. 動的グループを作成し、すべてのワークステーションをインポートする
- B. タイプ=ワークステーション割り当ての静的グループを作成する
- C. 静的グループを作成し、すべてのワークステーションをインポートする
- D. タイプ=ワークステーション割り当ての動的グループを作成する
正解:D
解説:
The best method to ensure all workstation hosts are added to the group is to create a Dynamic Group with Type=Workstation Assignment. A Dynamic Group is a group that automatically updates its membership based on certain criteria or filters. A Type=Workstation Assignment filter will match all hosts that have the workstation type assigned in their Active Directory domain. This way, any new or existing workstation hosts will be added to the group without manual intervention1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 24
ホスト管理ページでホストを対象にしたフィルタリングを実行する場合、大文字と小文字が区別されないフィルタ バー属性はどれですか。
- A. ユーザー名
- B. ドメイン
- C. モデル
- D. ホスト名
正解:D
解説:
When performing targeted filtering for a host on the Host Management Page, the filter bar attribute that is not case-sensitive is Hostname. The Hostname attribute allows you to filter hosts by their computer name or DNS name. The Hostname filter is not case-sensitive, meaning that it will match hosts regardless of the capitalization of their names. For example, filtering by hostname=DESKTOP-1234 will match hosts with names such as DESKTOP-1234, desktop-1234, or Desktop-12342.
References: 2: Cybersecurity Resources | CrowdStrike
質問 # 25
ホスト管理ページからホストの「検出を無効にする」をクリックした後に、コンソールの検出に何が起こるかを最もよく説明するものは何ですか?
- A. ホストの既存の検出は残りますが、今後コンソールに新しい検出は表示されません。
- B. ホストの検出はコンソールから直ちに削除され、今後はコンソールに新しい検出は表示されなくなります。
- C. ホストの予防策は無効になります
- D. ホストの検出を無効にすることはできません
正解:B
解説:
The option that best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page is that the detections for the host are removed from the console immediately and no new detections will display in the console going forward. The "Disable Detections" feature allows you to enable or disable the detection and prevention capabilities of the Falcon sensor on a specific host. When you disable detections for a host, the sensor will stop sending any detection or prevention events to the Falcon console, and any existing events for that host will be removed from the console. When you enable detections for a host, the sensor will resume sending any new detection or prevention events to the Falcon console, but any previous events for that host will not be restored to the console1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 26
ホストを動的グループではなく静的グループに割り当てるのはなぜですか?
- A. グループに複数のオペレーティングシステムのホストを含めたい場合
- B. ホストをグループに自動的に割り当てる必要があります
- C. グループメンバーシップを自動的に変更したくない
- D. 1000台以上のホストを管理しています
正解:C
解説:
The reason why you would assign hosts to a static group instead of a dynamic group is that you do not want the group membership to change automatically. A Static Group is a group that requires manual assignment or removal of hosts. A Static Group will not update its membership based on any criteria or filters. This way, you can have more control over which hosts belong to the group and prevent any unwanted changes1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 27
ユーザーがセンサーのインストールを開始すると、ログはどこにありますか?
- A. %LOCALAPPDATA%\ログ
- B. %SYSTEMROOT%\Temp
- C. % LOCALAPP D ATA%\Temp p
- D. %SYSTEMROOT%\Logs
正解:B
解説:
When a user initiates a sensor install, the logs can be found in %SYSTEMROOT%\Temp. This folder contains temporary files and folders created by the system or applications, including the sensor installation logs. The sensor installation logs have names that start with CSFalconContainer and end with .log, such as CSFalconContainer-2023-08-31_11-23-21.log. These logs can help you troubleshoot any issues or errors that may occur during the sensor installation process3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
質問 # 28
Falcon プラットフォームにおける会社のイベント データ保持制限を知ることが重要なのはなぜですか?
- A. クエリでは、検索したい日付に関連付けられたデータプールを指定する必要があります。
- B. これは必要ありません。クエリで「全期間」を選択するだけで、すべてのデータを検索できます。
- C. 保存期間を超えて過去のイベントデータを検索することはできません
- D. プロセスレコードなどのデータはイベントデータよりも短い期間保持されます
正解:C
解説:
It is important to know your company's event data retention limits in the Falcon platform because you will not be able to search event data into the past beyond your retention period. The retention period is the amount of time that event data is stored in the Falcon Cloud, and it may vary depending on your subscription plan and settings. The other options are either incorrect or not related to knowing your retention limits.
Reference: CrowdStrike Falcon User Guide, page 48.
質問 # 29
封じ込めポリシーに IP アドレスを追加するタイミングを最もよく表すシナリオはどれですか。
- A. 組織には、Falcon コンソールにアクセスするために必要な追加の IP アドレスがあります。
- B. 組織には、ホストがネットワークに含まれているときにアクセスする必要があるリソースがあります。
- C. 新しいアナリストグループは、ネットワーク封じ込め下にホストを配置できる必要があります。
- D. ホストのIPアドレスに基づいてネットワーク封じ込めプロセスを自動化したい
正解:B
解説:
The scenario that best describes when you would add IP addresses to the containment policy is that your organization has resources that need to be accessible when hosts are network contained. As explained in the previous question, adding IP addresses to the containment policy allows you to create an allowlist of trusted IP addresses that can communicate with your contained hosts. This can be useful when you need to isolate a host from the network due to a potential compromise or investigation, but still want to allow it to access certain resources or services that are essential for your organization's operations or security2.
References: 2: Cybersecurity Resources | CrowdStrike
質問 # 30
アナリストから、ここ数日、ワークフローによってトリガーされた通知を受信していないという報告がありました。潜在的な障害を最初にどこで確認すればよいでしょうか?
- A. カスタムアラート履歴
- B. ワークフロー監査ログ
- C. Falcon UI 監査証跡
- D. ワークフロー実行ログ
正解:D
解説:
The Workflow Execution log in the Workflow Management option allows you to view the status and results of workflow executions triggered by detection events. You can filter the log by workflow name, status, start and end time, and detection ID. You can also view the details of each execution, including the actions performed, the output received, and any errors encountered. This log can help you troubleshoot potential failures or issues with your workflows1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 31
ホストがネットワーク封じ込め状態に置かれた場合、次のどれが正しいですか?
- A. ホストマシンはネットワークトラフィックを送受信できません
- B. ホストマシンは、Falcon Cloud との間のトラフィックとファイアウォールポリシーで許可されているトラフィックを除き、ネットワークトラフィックを送受信できません。
- C. ホストマシンは、Falcon Cloud および封じ込めポリシーで許可リストに登録されているリソース以外とのネットワークトラフィックを送受信できません。
- D. ホストマシンはローカルネットワーク外でネットワークトラフィックを送受信できません
正解:C
解説:
When a host is placed in Network Containment, the host machine is unable to send or receive network traffic except to/from the Falcon Cloud and any resources allowlisted in the Containment Policy. This allows users to isolate a host from the network, while still allowing it to communicate with the Falcon Cloud and other essential services. The other options are either incorrect or not true of Network Containment.
Reference: CrowdStrike Falcon User Guide, page 40.
質問 # 32
CrowdStrike Falcon でセンサー更新ポリシーを持つグループを使用する目的は何ですか?
- A. 特定のホストにセンサーのバージョンを制御的に割り当てることを可能にする
- B. Falcon アップデートのインストール順序を優先し、アップデートが一度にインストールされてネットワークの混雑が発生しないようにします。
- C. 同じビジネスユニット内の他のホストとグループ化する
- D. Falcon がインストールされた順序に従ってホストをグループ化し、アップデートが毎回同じ順序でインストールされるようにします。
正解:A
解説:
The purpose of using groups with Sensor Update policies in CrowdStrike Falcon is to allow the controlled assignment of sensor versions onto specific hosts. This allows users to manage the sensor updates for different hosts based on their needs and preferences, such as testing, staging or production. The other options are either incorrect or not related to using groups with Sensor Update policies. Reference: [CrowdStrike Falcon User Guide], page 38.
質問 # 33
環境内に誤検知の機械学習検出が多数あることが判明しました。これらは、ベンダーがカスタム作成した単一のバイナリによって発生しており、そのバイナリは多数のエンドポイントで実行されています。今後、これらを防ぐ最善の方法は何でしょうか?
- A. IOC 管理を使用して、問題のバイナリのハッシュを追加し、アクションを「ブロック、検出を非表示」に設定します。
- B. IOC 管理を使用して、問題のバイナリのハッシュを追加し、アクションを「許可」に設定します。
- C. サポートに連絡し、機械学習の設定を変更してこの検出が含まれないように依頼してください。
- D. IOC 管理を使用して、問題のバイナリのハッシュを追加し、アクションを「アクションなし」に設定します。
正解:B
解説:
to match any number of characters including none while not matching beyond path separators (\ or /) and double asterisks are used to recursively match zero or more directories that fall under the current directory.
質問 # 34
除外構文に基づいて記録、検出、または防止されないマルウェアやその他の攻撃などの追加のセキュリティ リスクが発生する可能性があるため、次のどれを細心の注意を払って使用する必要がありますか?
- A. IOA の除外
- B. センサーの可視性除外
- C. IOC 除外
- D. 機械学習の除外
正解:A
解説:
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary2.
References: 2: Cybersecurity Resources | CrowdStrike
質問 # 35
Windows センサー更新ポリシーには、「自動」センサー バージョン更新オプションがいくつありますか?
- A. 0
- B. 1
- C. 2
- D. 3
正解:C
解説:
There are three "Auto" sensor version update options available for Windows Sensor Update Policies: Auto - N-1, Auto - TEST-QA and Auto - Latest. These options allow the administrator to automatically update the sensor version to the previous stable version, the latest test version or the latest stable version, respectively.
Reference: [CrowdStrike Falcon User Guide], page 38.
質問 # 36
センサー更新ポリシーを OS (Windows、Mac、Linux) ごとに構成する必要があるのはなぜですか?
- A. 監査と変更管理を支援する
- B. センサー更新ポリシーは OS に依存します
- C. これは誤りです。1つのポリシーをすべてのオペレーティングシステムに適用できます。
- D. センサーと予防ポリシーを展開パッケージにまとめる
正解:B
解説:
Sensor Update policies need to be configured for each OS (Windows, Mac, Linux) because Sensor Update policies are OS dependent. A Sensor Update policy is a policy that controls how and when the Falcon sensor is updated on a host. Sensor Update policies are specific to each operating system type, as different operating systems have different sensor versions, features, and requirements. Therefore, you need to create and assign separate Sensor Update policies for each operating system type in your environment1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 37
ネットワーク封じ込めポリシーの目的は何ですか?
- A. 割り当てられた予防ポリシーの積極性を高める
- B. プライバシーのためにネットワークを分割する
- C. 侵害されたホストがネットワークに与える影響を制限する
- D. ネットワークアクティビティの可視性を高める
正解:C
解説:
The goal of a Network Containment Policy is to limit the impact of a compromised host on the network. This policy allows users to isolate a host from the network, while still allowing it to communicate with the Falcon Cloud and other essential services. This can help prevent further damage or data exfiltration from a compromised host. The other options are either incorrect or not related to the policy. Reference: [CrowdStrike Falcon User Guide], page 40.
質問 # 38
除外を適用できるものは何ですか?
- A. 管理者が選択した個々のホスト
- B. すべてのホストまたは指定されたグループ
- C. デフォルトのホストグループのみ
- D. 管理者が選択したグループのみ
正解:B
解説:
The option that describes what exclusions can be applied to is that exclusions can be applied to either all hosts or specified groups. An exclusion is a rule that defines what files, folders, processes, IP addresses, or domains should be excluded from detection or prevention by the Falcon sensor. You can create and manage exclusions in the Exclusions page in the Falcon console. You can apply exclusions to either all hosts in your environment or to specific host groups that you select. You cannot apply exclusions to individual hosts selected by the administrator.
References: : [Cybersecurity Resources | CrowdStrike]
質問 # 39
次のフィルターのうち、ホスト管理ページで使用できないものはどれですか?
- A. グループ
- B. OS バージョン
- C. ホスト名
- D. ユーザー名
正解:D
解説:
Username is not an available filter on the Hosts Management page. The Hosts Management page allows you to view and manage all the hosts in your environment that have Falcon sensors installed. You can filter the hosts by hostname, group, OS version, sensor version, last seen date, health events, detections, and preventions. You can also perform actions such as assigning hosts to groups, updating sensor policies, uninstalling sensors, or isolating hosts1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
質問 # 40
......
CCFA-200日本語問題集はCrowdStrike Certified Falcon Administrator認証済み試験問題と解答:https://jp.fast2test.com/CCFA-200-JPN-premium-file.html