CCFA-200B Exam Questions
252 real CCFA-200B exam questions with expert-verified answers and explanations. Page 5 of 6.
- Question #201
Which report would show you an overview of the top ten most-applied policies by sensors in your environment?
- Question #202
There are a significant number of false positive detections from your developers that are getting blocked and quarantined by Falcon. What Indicator of Compromise (IOC) action would...
- Question #203
From the Host management page, what is the best field to filter by for Domain Controllers to obtain sensor version information?
- Question #204
You have been asked by your Server management team to provide a list of all Servers that have a "TIER3" Sensor grouping tag. What method will allow you to export a .csv file with t...
- Question #205
Which default user role will allow you to see all analyst session details?
- Question #206
Where would you apply a configuration to allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained?
- Question #207
Which ML exclusion pattern would be the most accurate for all .exe binaries in "C:\Program Files\Software\", including any subfolders of Software?
- Question #208
You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that...
- Question #209
When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?
- Question #210
You will be testing detections with pentest and security tooling on your host. How can a workflow be created to automatically assign any detection related to your pentest to yourse...
- Question #211
What best describes the effect of disabling detections for a host?
- Question #212
To improve the organization's security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a...
- Question #213
What log would you use to investigate unusual activity involved with a script interfacing with the Falcon platform?
- Question #214
What happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
- Question #215
You are tasked with creating a "Workstations" host group to encompass ALL workstations in your environment. Which dynamic grouping criteria would best accomplish this task?
- Question #216
How can you search for multiple hostnames at the same time via Host Management?
- Question #217
Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?
- Question #218
As a Falcon Administrator, you would like to tune your Prevention Policies and compare the number of detections that would have resulted in the last 30 days depending on which dete...
- Question #219
What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode (RFM)?
- Question #220
A server was added to a new host group that has a different sensor update and prevention policy applied. Even though the server has been online for more than 30 minutes, the polici...
- Question #221
By default, how many days without successful communication must pass before a host no longer appears in the Falcon console?
- Question #222
After successfully installing Falcon on a new employee's laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you c...
- Question #223
You are creating a new host group that needs to contain all of the servers in your environment regardless of the installed operating system. Which filter should be applied to the g...
- Question #224
Which report provides a filterable high-level overview of host information such as OS version, Device Type and Machine Domain, and also provides an active sensor heat map for a qui...
- Question #225
Which statement best describes user permissions in Falcon?
- Question #226
Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections...
- Question #227
What could cause your Windows host to be in Reduced Functionality Mode (RFM)?
- Question #228
What are the three required parts of a Fusion SOAR workflow condition?
- Question #229
What is the primary concern with Windows sensors going into Reduced Functionality Mode (RFM)?
- Question #230
What information can be found in the Real Time Response (RTR) Audit Log?
- Question #231
You are deploying the Falcon sensor to a total of 500 hosts. Hosts in an Organizational Unit (OU) will need a specific exclusion that was previously identified. This OU is expected...
- Question #232
Using Host setup and management inside the Falcon Console, how can you display sensors in Reduced Functionality Mode (RFM)?
- Question #233
What default user role can manage API credentials?
- Question #234
A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this...
- Question #235
You want to add an additional layer of security to high-risk RTR commands for your environment. Where would you configure MFA for RTR within the UI?
- Question #236
Your security team is noticing that certain privacy-sensitive information such as the URL, HTTP Header and POST bodies are missing from HTTP related detections. What is likely the...
- Question #237
When creating a machine learning exclusion with glob syntax, what are the three items you can target for exclusion?
- Question #238
Where can you find hosts that have been offline for ten minutes or longer?
- Question #239
What are the two automated triggers that cause a Fusion SOAR workflow to run?
- Question #240
What are the required components to manually install Falcon Sensor on MacOS?
- Question #241
You need to create a rule to block all process executions of Telegram in your environment. Which custom IOA rule configuration would accomplish this?
- Question #242
What is true about User Accounts created by the Falcon Administrator?
- Question #243
You have created a new static host group to test a newly created sensor update policy, and need to add 500 servers into the group. You want to upload a list of hosts to Falcon for...
- Question #244
Leadership has asked for a monthly report on number of hosts by OS version, device type, and geographic location. What dashboard option includes this information?
- Question #245
You need to be aware of which policies are the most used as new hosts are being added to your CID. Where could you easily find a review of the top ten sensor update, prevention, an...
- Question #246
Your incident responder team is in the process of migrating their existing workflows into Fusion SOAR workflows so that they will execute natively in Falcon. The team reports the w...
- Question #247
To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group...
- Question #248
How would you reset an API secret?
- Question #249
During a simulated training exercise with your security team, an analyst used Falcon to network contain a host. It was then discovered that containing this specific host interrupte...
- Question #250
Which prevention policy setting monitors contents of scripts and shells for execution of malicious content?