CCFA-200B Exam Questions
252 real CCFA-200B exam questions with expert-verified answers and explanations. Page 2 of 6.
- Question #51
What type of information is found in the Linux Sensors Dashboard?
- Question #52
Why would you assign hosts to a static group instead of a dynamic group?
- Question #53
What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?
- Question #54
Which of the following uses Regex to create a detection or take a preventative action?
- Question #55
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
- Question #56
What statement is TRUE about managing a user's role?
- Question #57
Which Real Time Response role will allow you to see all analyst session details?
- Question #58
Which command would tell you if a Falcon Sensor was running on a Windows host?
- Question #59
On which page of the Falcon console can one locate the Customer ID (CID)?
- Question #60
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow rem...
- Question #61
Which of the following controls the speed in which your sensors will receive automatic sensor updates?
- Question #62
Which of the following tools developed by Crowdstrike is intended to help with removal of the CrowdStrike Windows Falcon Sensor?
- Question #63
When a user initiates a sensor installs, where can the logs be found?
- Question #64
After agent installation, an agent opens a permanent___connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is termina...
- Question #65
Which of the following best describes what the Uninstall and Maintenance Protection setting controls within your Sensor Update Policy?
- Question #66
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
- Question #67
Where can you find your company's Customer ID (CID)?
- Question #68
A Falcon Administrator is trying to use Real-Time Response to start a session with a host that has a sensor installed but they are unable to connect. What is the most likely cause?
- Question #69
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
- Question #70
When troubleshooting the Falcon Sensor on Windows, what is the correct parameter to output the log directory to a specified file?
- Question #71
You have been asked to troubleshoot why Script Based Execution Monitoring (SBEM) is not enabled on a Falcon host. Which report can be used to determine if this is an issue with an...
- Question #72
What information does the API Audit Trail Report provide?
- Question #73
What three things does a workflow condition consist of?
- Question #74
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
- Question #75
In order to quarantine files on the host, what prevention policy settings must be enabled?
- Question #76
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the foll...
- Question #77
Which of the following scenarios best describes when you would add IP addresses to the containment policy?
- Question #78
How many days will an inactive host remain visible within the Host Management or Trash pages?
- Question #79
Which of the following pages provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System?
- Question #80
What best describes what happens to detections in the console after clicking "Enable Detections" for a host which previously had its detections disabled?
- Question #81
When a Linux host is in Reduced Functionality Mode (RFM) what telemetry and protection is still offered?
- Question #82
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
- Question #83
What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
- Question #84
Which report lists counts of sensors in Reduced Functionality Mode (RFM) for all operating system types, and tracks how long a sensor version will be supported?
- Question #85
Which statement is TRUE regarding disabling detections on a host?
- Question #86
Which of the following is TRUE regarding disabling detections for a host?
- Question #87
What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
- Question #88
Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?
- Question #89
What is the purpose of the Default Sensor Policy?
- Question #90
What best describes the relationship between Sensor Update policies and Operating Systems?
- Question #91
Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
- Question #92
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however, when applying the new prevention policy this group is not appearing in the li...
- Question #93
What is the purpose of the Machine-Learning Prevention Monitoring Report?
- Question #94
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
- Question #95
The Customer ID (CID) is important in which of the following scenarios?
- Question #96
What may prevent a user from logging into Falcon via single sign-on (SSO)?
- Question #97
When a host belongs to more than one host group, how is sensor update precedence determined?
- Question #98
A sensor that has not contacted the Falcon cloud will be automatically deleted from the hosts list after how many days?
- Question #99
You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?
- Question #100
What can exclusions be applied to?