CrowdStrike Certified SIEM Engineer Sample Questions:
1. What is the most appropriate action if a third-party connector is disconnected and no longer ingesting data?
A) Change all searches to Falcon-only data
B) Ignore it until the monthly ingestion report updates
C) Delete the related parser immediately
D) Review connector health and reconnect or reauthorize the integration
2. Which sequence correctly describes the process for duplicating a workflow in Fusion SOAR?
A) Go to Fusion SOAR > Workflow Management > Select "All Workflows" tab > Right-click on the workflow to duplicate > Select "Clone Workflow" > Modify workflow parameters > Click "Validate" > Set workflow status > Click Apply Changes
B) Go to Fusion SOAR > Fusion SOAR > Workflows > Click Open (three dots) menu for the workflow you want to duplicate > Click "Duplicate workflow" > Update and rename the duplicated workflow > Click Save and exit to save the updated workflow
C) Go to Fusion SOAR > Fusion SOAR > Workflows > Find the workflow to duplicate > Click the workflow name > Select "Duplicate" from Actions menu > Edit the workflow configuration > Click
"Create" to generate the new workflow > Set Status to On
D) Go to Fusion SOAR > Fusion SOAR > Workflows > Select the checkbox next to the workflow you want to duplicate > Click "Actions" at the top of the page > Select "Create Copy" > Edit workflow name and description > Configure trigger conditions > Click Next > Review workflow canvas > Click Finish
3. Review the log sample below:
What type of parser should be used to extract fields and values from this log?
A) CSV
B) Key-Value
C) XML
D) JSON
4. You are a Next-Gen SIEM Engineer responsible for parser creation. An internal requirement is to maintain both the Vendor and ECS field names within the Fields panel in Advanced Event Search.
What is the correct method for adding the ECS field while maintaining the Vendor field in a parser?
A) Assignment Operator
B) Regular Expression Field Extraction
C) As Parameter
D) Field Function
5. You are creating an AI-generated parser to process and normalize log data from various sources.
How would you ensure the parser accurately interprets and categorizes the log data?
A) Create a set of log examples to match log patterns from different sources
B) Ensure the parser has a minimum of 100 lines
C) Write the parser in a high-level programming language (Python or Java)
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: A | Question # 4 Answer: A | Question # 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Una

