CrowdStrike CCSE-204 試験概要:
| 認定ベンダー: | CrowdStrike |
|---|---|
| 試験名: | CrowdStrike認定SIEMエンジニア (CCSE-204) |
| 試験番号: | CCSE-204 |
| 対応言語: | 英語 |
| 試験時間: | 90 分 |
| 受験料: | 250米ドル |
| 出題数: | 60 |
| 試験形式: | 多肢選択式 |
| 関連資格: | CrowdStrike認定Falcon管理者 CrowdStrike認定セキュリティオペレーションエンジニア |
| 認定の有効期間: | 3年間 |
| 合格点: | 非公開 |
| 推奨トレーニング: | CrowdStrike Next-Gen SIEM関連トレーニング |
| 受験申し込み: | Pearson VUEでの受験登録 |
| サンプル問題: | CrowdStrike CCSE-204 サンプル問題 |
| 受験方法: | Pearson VUE OnVUEによるオンライン監視付き受験、またはPearson VUE試験会場での対面受験 |
| 前提条件: | 推奨要件:Falcon Next-Gen SIEMの実務経験が6か月以上であること。受験に必須の前提条件は設けられていません |
| 公式シラバスのURL: | https://www.crowdstrike.com/services-and-training/certification/ |
CrowdStrike CCSE-204 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| データの取り込み | 20% | - コネクタの構成要素と管理方法 - 取り込み方式と統合戦略 - フリート管理およびログコレクターの導入 - 自社提供データソースと第三者提供データソースの違い - 標準搭載およびカスタムデータコネクタの設定 - データ取り込みおよび接続に関する問題のトラブルシューティング |
| データ解析 | 20% | - ログ形式の識別と処理方法 - CrowdStrikeの解析基準とデータの正規化 - AI生成解析ルールと高度な構文 - 解析エラーの監視と解決方法 - 解析ルールの作成、変更、複製 - 解析ルールのテストと妥当性確認 |
| 自動化とシステム統合 | 20% | - APIアクセスとトークンの管理 - Falcon Fusion SOARによるワークフローの設計と自動化 - FalconPyおよびその他ツールとの連携 - 自動応答と問題解決の実装 - 外部システムとの統合 |
| コンテンツの作成 | 20% | - コンテンツの展開とバージョン管理 - ダッシュボードの作成とカスタマイズ - 相関ルールの作成、調整、管理 - 自社提供検知ロジックと第三者提供検知ロジックの違い - 参照用ファイルの管理と活用方法 - CQLクエリの設計、作成、最適化 |
| ユーザー管理 | 20% | - カスタムロールの作成と権限の付与 - Multi-factor authentication (MFA)の設定 - SSO/SAMLの設定およびクレームのマッピング - Role-based access control (RBAC)および標準ロール - 監査ログの監視と活用方法 - リポジトリレベルのアクセス制御 |
CrowdStrike Certified SIEM Engineer 認定 CCSE-204 試験問題:
問題 #1
What is the correct mode to enroll LogCollector into Fleet Management with configuration of the log sources stored and managed centrally in Next-Gen SIEM?
A. Central
B. localConfig
C. Complete
D. Full
問題 #2
You are reviewing a lookup file to determine whether an event was successfully parsed during ingestion.
Which metadata field indicates the event's parsing status?
A. @event_parsed
B. @error_msg
C. @ingesttimestamp
D. @rawstring
問題 #3
You are performing a search query using data from the Falcon Sensor and third-party data connectors.
Which Advanced Event Search data source should you choose?
A. Falcon
B. All
C. Third-party
D. Custom
問題 #4
Which SIEM capability allows analysts to enrich Falcon alerts with external threat intelligence feeds to improve investigation context?
A. Enrichment
B. Compression
C. Parsing
D. Aggregation
問題 #5
How does a first-party detection differ from a third-party detection?
A. First-party detections are those native to the platform, while third-party detections are generated from data sources external to the platform
B. First-party detections are a higher severity than third-party detections and should be triaged first
C. First-party detections are those native to the platform, while third-party detections are those created by the customer's security team
D. First-party detections can be seen by all users, while third-party detections require special roles and permissions to be viewed
解説:
| 問題 #1 正解: A | 問題 #2 正解: A | 問題 #3 正解: B | 問題 #4 正解: A | 問題 #5 正解: A |














1385 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
