Pre-Summer Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

CCSE-204 CrowdStrike Certified SIEM Engineer Questions and Answers

Questions 4

What are the four required CPS-compliant Event parser tags?

Options:

A.

event.category

event.kind

event.module

event.outcome

B.

event.category

event.dataset

event.kind

event.outcome

C.

event.dataset

event.kind

event.module

event.outcome

Buy Now
Questions 5

In the Next-Gen SIEM Connector Dashboard, what is the maximum retention period for which you can query third-party data ingestion metrics?

Options:

A.

30 days

B.

60 days

C.

90 days

D.

180 days

Buy Now
Questions 6

You want a consistent view of events from various data sources.

Which ECS field type should you normalize?

Options:

A.

Base Fields

B.

Extended Fields

C.

Detection Fields

D.

Core Fields

Buy Now
Questions 7

You notice a larger than expected ingest delay from one of your high-volume streaming log collectors.

Which setting should you increase on the log collector to improve performance?

Options:

A.

Amount of available disk space

B.

Available source throughput

C.

Number of concurrent requests a sink is using

D.

Default memory queue size

Buy Now
Questions 8

Which field should be used in a correlation rule when detections must be based on the original event occurrence time?

Options:

A.

@ingesttimestamp

B.

@timestamp

C.

@rawstring

D.

@id

Buy Now
Questions 9

When deploying the Falcon Log Collector using the commands in the CrowdStrike Fleet Management interface, what is the correct service name?

Options:

A.

flc-api

B.

humio-collector

C.

logscale-collector

D.

flc-collector

Buy Now
Questions 10

Which combination of scope and permissions must be configured to create an API token that allows you to create and get the results of a query job in Next-Gen SIEM?

Options:

A.

NGSIEM with both write and execute permissions

B.

NGSIEM with read permissions only

C.

NGSIEM with both read and write permissions

D.

NGSIEM with write permissions only

Buy Now
Questions 11

You need to provide a colleague the appropriate role to allow for configuration of connectors and creation of SOAR automations in Next-Gen SIEM.

Which role will provide these permissions while also maintaining least privilege?

Options:

A.

NG SIEM Security Lead

B.

NG SIEM Analyst

C.

Falcon Security Lead

D.

Custom role

Buy Now
Questions 12

Which default role will maintain least privilege and allow for creation and management of parsers?

Options:

A.

NG SIEM Analyst

B.

NG SIEM Security Lead

C.

NG SIEM Administrator

D.

NG SIEM Analyst – Read Only

Buy Now
Questions 13

You need to ingest data from a custom internal application hosted on-prem. The application writes logs to a file on a syslog server.

Which data connector would you use?

Options:

A.

Google Cloud Pub / Sub Data Connector

B.

HTTP Event Connector

C.

Amazon S3 Data Connector

D.

Azure Virtual Machines Data Connector

Buy Now
Questions 14

What is the purpose of labels in Fleet Management?

Options:

A.

Set passwords for collector instances

B.

Categorize collectors for group configurations

C.

Monitor network traffic

D.

Assign IP addresses to collectors

Buy Now
Questions 15

You suspect that an API key you recently generated has been compromised.

What should you do?

Options:

A.

Regenerate a new API key directly from the platform

B.

Search the audit logs for the connector creation event and replicate it

C.

View the API key details in the platform and clone a new API key

D.

Contact CrowdStrike Support to retrieve and send the key to you

Buy Now
Questions 16

You are onboarding a log source that includes a timestamp with a different timezone.

How should you address any time parsing errors that occur?

Options:

A.

Clone the parser and manually apply the timezone parameter

B.

Adjust the log source to reflect the correct timezone before sending logs

C.

Clone the parser and change the timestamp field name

D.

Clone the parser and drop the timestamp field, use ingesttimestamp instead

Buy Now
Questions 17

Which Falcon LogScale Collector output format would you use if your downstream SIEM requires raw nested event data?

Options:

A.

Syslog

B.

CEF

C.

JSON

D.

LEEF

Buy Now
Questions 18

You are performing a search query using data from the Falcon Sensor and third-party data connectors.

Which Advanced Event Search data source should you choose?

Options:

A.

All

B.

Falcon

C.

Third-party

D.

Custom

Buy Now
Exam Code: CCSE-204
Exam Name: CrowdStrike Certified SIEM Engineer
Last Update: Apr 11, 2026
Questions: 62
CCSE-204 pdf

CCSE-204 PDF

$25.5  $84.99
CCSE-204 Engine

CCSE-204 Testing Engine

$30  $99.99
CCSE-204 PDF + Engine

CCSE-204 PDF + Testing Engine

$40.5  $134.99