CCFA-200B Exam Questions
252 real CCFA-200B exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1Sensor Deployment and Management
What command should be run to verify if a Windows sensor is running?
Windows sensorsc querysensor statussensor verification - Question #2Detection and Prevention Policies
Which option allows you to exclude behavioral detections from the detections page?
IOA exclusionbehavioral detectionsexclusion typesdetections page - Question #3Monitoring and Alerting
What are custom alerts based on?
custom alertsalert templatesFalcon consolealerting - Question #4API and Integrations
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
API clientAPI secretAPI managementcredential security - Question #5Sensor Deployment and Management
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
Reduced Functionality ModeRFMWindows patchsensor compatibility - Question #6Reporting and Dashboards
Which of the following is TRUE of the Logon Activities Report?
Logon Activities Reportuser activityreportinglast logon - Question #7Real Time Response
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?
Real Time ResponseRBACcustom scriptsuser roles - Question #8Workflow Automation
What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?
workflowstriggersconditionsactions - Question #9API and Integrations
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?
API client secretAPI securitycredential retrievalAPI management - Question #10Sensor Deployment and Management
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?
sensor communicationTCP 443HTTPSnetwork requirements - Question #11Sensor Deployment and Management
What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?
RFMMicrosoft updatessensor compatibilityWindows updates - Question #12Host Management
On which page of the Falcon console would you create sensor groups?
host groupssensor groupsFalcon console navigationgroup management - Question #13Response and Containment
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration...
network containmentcontainment policyIP allowlistremediation - Question #14Detection and Prevention Policies
Which of the following is TRUE regarding Falcon Next-Gen AntiVirus (NGAV)?
NGAVdetection slidersprevention sliderspolicy configuration - Question #15Sensor Deployment and Management
What is the purpose of using groups with Sensor Update policies in CrowdStrike Falcon?
sensor update policyhost groupssensor versionsupdate management - Question #16API and Integrations
What impact does disabling detections on a host have on an API?
detection suppressionStreaming APIDetectionSummaryEventAPI integration - Question #17Sensor Deployment and Management
Under which scenario can Sensor Tags be assigned?
sensor tagssensor installationhost taggingtag assignment - Question #18Detection and Prevention Policies
Custom IOA rules are defined using which syntax?
Custom IOAregexIOA rule syntaxrule creation - Question #19Monitoring and Alerting
With Custom Alerts, it is possible to __________.
custom alertsemail notificationalert capabilitiesalerting - Question #20Detection and Prevention Policies
How do you assign a Prevention policy to one or more hosts?
prevention policyhost groupspolicy assignmentpolicy management - Question #21Prevention Policy and IOC Management
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they...
IOC Managementhash blockingSHA256malware prevention - Question #22Prevention Policy Configuration
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
exclusion patternsglob syntaxfile path exclusionprevention policy - Question #23Detection and Response
When a host is placed in Network Containment, which of the following is TRUE?
network containmenthost isolationFalcon Cloudresponse actions - Question #24Prevention Policy and IOC Management
When would the No Action option be assigned to a hash in IOC Management?
IOC ManagementNo Action optionindicator managementhash disposition - Question #25Sensor Deployment and Management
In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor U...
sensor update policyuninstall protectionsensor versionmaintenance protection - Question #26Prevention Policy Configuration
Once an exclusion is saved, what can be edited in the future?
exclusion managementpolicy editingexclusion pattern - Question #27Prevention Policy Configuration
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
sensor-based machine learningoffline protectionNGAVunknown executable analysis - Question #28Sensor Deployment and Management
How do you find a list of inactive sensors?
inactive sensorssensor reportinghost managementsensor aging report - Question #29Prevention Policy Configuration
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
machine learningprevention policy tuningML monitoring reportprevention levels - Question #30Detection and Response
Why is the ability to disable detections helpful?
detection managementdisable detectionstest environmentfalse positive - Question #31Investigation and Reporting
The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.
logon activities reportuser investigationauthenticationreporting - Question #32Workflow and Automation
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
workflow automationexecution lognotification failuretroubleshooting - Question #33Workflow and Automation
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customi...
workflow automationparallel actionemail notificationworkflow configuration - Question #34Platform Administration
Which of the following is NOT an available filter on the Hosts Management page?
host managementfilteringhost searchplatform navigation - Question #35Prevention Policy Configuration
What is the primary purpose of using glob syntax in an exclusion?
glob syntaxexclusion patternsfile and folder exclusiondetection exclusions - Question #36Platform Administration
How are user permissions set in Falcon?
RBACuser rolespermissions managementuser administration - Question #37Sensor Deployment and Management
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
sensor versionhost managementsensor reportingendpoint identification - Question #38Sensor Deployment and Management
Which is the correct order for manually installing a Falcon Package on a macOS system?
macOS sensor installationsensor deploymentregistration processFalcon package - Question #39Prevention Policy Configuration
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Pr...
machine learning levelsprevention policycautious modecoexistence testing - Question #40Investigation and Reporting
How does the Unique Hosts Connecting to Countries Map help an administrator?
network visualizationglobal connections mapthreat intelligencedashboard analytics - Question #41Sensor Deployment and Management
On a Windows host, what is the best command to determine if the sensor is currently running?
sensor statusWindows commandscsagentsc query - Question #42Sensor Deployment and Network Configuration
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
certificate pinningSSL inspectiondeep packet inspectionnetwork configuration - Question #43Host Setup and Management
Which is a filter within the Host setup and management > Host management page?
host managementconsole filtersOUhost search - Question #44Host Setup and Management
When creating a Host Group for all Workstations in an environment, what is the best method to ensure all workstation hosts are added to the group?
host groupsdynamic groupsworkstation assignmentgroup membership - Question #45Prevention Policy Configuration
When the Notify End Users policy setting is turned on, which of the following is TRUE?
end user notificationsprevention policypop-up alertspolicy settings - Question #46Sensor Deployment and Management
If a user wanted to install an older version of the Falcon sensor, how would they find the older installer file?
sensor installationolder versionssensor downloadsdeployment - Question #47Sensor Update Management
Which of the following best describes the Default Sensor Update policy?
sensor update policydefault policycatch-all policypolicy assignment - Question #48Prevention Policy Configuration
Under the "Next-Gen Antivirus: Cloud Machine Learning" setting there are two categories, one of them is "Cloud Anti-Malware" and the other is:
cloud machine learningAdware PUPnext-gen antivirusML categories - Question #49Sensor Update Management
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
sensor update policyplatform scopeMac policyOS-specific policies - Question #50Prevention Policy Configuration
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?
machine learning sliderscautious settingmalware confidenceML sensitivity