Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFH-202 Topic 10 Question 38 Discussion

Actual exam question for CrowdStrike's CCFH-202 exam
Question #: 38
Topic #: 10
[All CCFH-202 Questions]

With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of the following outlines the steps required to properly create a custom alert rule?

Show Suggested Answer Hide Answer
Suggested Answer: B

These are the steps required to properly create a custom alert rule. Custom Alerts are a feature that allows you to configure email alerts using predefined templates so you're notified about specific activity in your environment. You can choose from various templates that cover different use cases, such as suspicious PowerShell activity, network connections to risky countries, etc. You can also preview the search results of the template before scheduling the alert. You do not need to create the query for the alert, setup the email template for the alert, or create a new custom template, as these are already provided by the predefined templates.


Contribute your Thoughts:

Frederica
3 days ago
Ha! Who needs custom alerts when you can just set your inbox to 'alert on every email'? That's the real pro tip here.
upvoted 0 times
...
Giovanna
4 days ago
Hmm, I'm torn between B and C. Previewing the search results could be useful, but C looks more comprehensive. I'll have to think about this one.
upvoted 0 times
...
Gussie
12 days ago
Hmm, that makes sense too. Let's review the options again.
upvoted 0 times
...
Allene
14 days ago
Option D seems a bit too complex. I'd go with C - it's more straightforward and covers the key steps.
upvoted 0 times
...
Gary
17 days ago
I think option C is the correct answer. Creating the query, setting up the email template, and then scheduling the alert seems like the logical flow to properly create a custom alert rule.
upvoted 0 times
Mattie
6 days ago
I agree, option C does seem like the correct answer. It's important to create the query first.
upvoted 0 times
...
...
Winfred
17 days ago
I disagree, I believe the answer is A, because you need to choose the template first.
upvoted 0 times
...
Gussie
17 days ago
I think the answer is C, because you need to create the query first.
upvoted 0 times
...

Save Cancel