Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

CCFA-200b CrowdStrike Falcon Certification Program Questions and Answers

Questions 4

How can you search for multiple hostnames at the same time via Host Management?

Options:

A.

Enter the multiple hostnames in the Hostname filter separating each by a comma

B.

Add the Hostname filter multiple times and enter separate hostnames into each filter

C.

Enter the multiple hostnames in the Hostname filter separating each by a decimal

D.

Add the Multiple Hostnames filter and enter your list of hostnames

Buy Now
Questions 5

What type of information is provided in sensor health report?

Options:

A.

User login history

B.

Local performance metrics

C.

Current operational status

D.

Network traffic patterns

Buy Now
Questions 6

What is the primary purpose of audit logs in Falcon?

Options:

A.

Trace file changes

B.

Track configuration changes

C.

Monitor system performance

Buy Now
Questions 7

What is the recommended approach for managing host groups over time?

Options:

A.

Create separate groups for each department

B.

Create groups based on IP ranges

C.

Maintain multiple overlapping host groups

D.

Minimize the number of groups

Buy Now
Questions 8

A new prevention policy has been created for assignment to the group named “Servers”. When you try to apply the policy, the “Servers” group is not available. What is the most likely reason the group is not available?

Options:

A.

The “Servers” group must be disabled first

B.

The “Servers” group already has a prevention policy applied to it

C.

Host type was not defined correctly within the prevention policy

D.

The new prevention policy should be enabled first

Buy Now
Questions 9

A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

B.

Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools

C.

Remove Host containment and update the host with all patches

D.

Create a Firewall Policy that allow lists your patch management tools

Buy Now
Questions 10

What is the fastest way to locate inactive sensors in the Falcon console?

Options:

A.

Sort hosts by Last Seen timestamp

B.

Export all host data to CSV

C.

Filter the Host Management page to show inactive hosts

D.

Search for hosts with no Agent ID

Buy Now
Questions 11

You have 100 hashes that have been prohibited by management and need to be blocked within your organization. Using Falcon, what is the best way to accomplish this?

Options:

A.

Navigate to Configure > IOC Management. Add a custom IOC. Add the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.

B.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block. Verify Custom Execution Blocking is active.

C.

Navigate to Configure > IOC Management. Add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.

D.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block and Alert. Verify Custom Blocking inside Execution Blocking is active.

Buy Now
Questions 12

In order to quarantine files on the host, what prevention policy settings must be enabled?

Options:

A.

Malware Protection and Windows Anti-Malware Execution Blocking

B.

Next-Gen Antivirus Prevention sliders and “Quarantine & Security Center Registration”

C.

Malware Protection and Custom Execution Blocking

D.

Behavior-Based Threat Prevention sliders and Advanced Remediation Actions

Buy Now
Questions 13

What action should you take to securely allow operating system update processes to occur during network containment?

Options:

A.

Ensure all internal network IPs are allowed

B.

Add IPs of update sources to the Containment policy

C.

Add sources to the Host Firewall policy

D.

Remove network containment to allow access

Buy Now
Questions 14

You are tasked with creating a “Workstations” host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?

Options:

A.

OU Workstation

B.

Grouping Tags Workstation

C.

Type: Workstation

D.

Platform Windows

Buy Now
Questions 15

What are the three required parts of a Fusion SOAR workflow condition?

Options:

A.

Operator, value, and source

B.

Alert, action, and schedule

C.

Trigger, parameter, and alert

D.

Parameter, operator, and value

Buy Now
Questions 16

When using Microsoft Windows, what command verifies that a Falcon Sensor is running?

Options:

A.

cswindiag.exe -status

B.

sc.exe query csagent

C.

netstat.exe -f

D.

sc.exe query falcon

Buy Now
Questions 17

Using Host setup and management inside the Falcon Console, how can you display sensors in Reduced Functionality Mode?

Options:

A.

From Host management, filter for RFM

B.

From Host status, filter for RFM

C.

From Sensor health, sort using the column heading Sensor status

D.

From Sensor status, click on the widget RFM

Buy Now
Questions 18

How are prevention policies assigned to hosts in the Falcon platform?

Options:

A.

Through host group membership

B.

Through direct host assignment

C.

Through IP address ranges

D.

Through manual configuration

Buy Now
Questions 19

Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?

Options:

A.

Installation and Maintenance Protection

B.

Sensor Version Control Protection

C.

Uninstall and Maintenance Protection

D.

Update and Management Protection

Buy Now
Questions 20

What is the primary concern with Windows sensors going into Reduced Functionality Mode?

Options:

A.

The sensors are unable to report any of their recorded events

B.

The sensors do not have full visibility into all events occurring on the host

C.

The hosts have been powered off or otherwise cannot communicate with the Falcon cloud

D.

The operating systems on these hosts have crashed

Buy Now
Questions 21

From the Host management page, what is the best field to filter by for Domain Controllers to obtain sensor version information?

Options:

A.

Sensor Version

B.

Type

C.

Platform

D.

OS Version

Buy Now
Questions 22

In addition to Host Groups, what other groups can a prevention policy be applied to?

Options:

A.

Operating System Groups

B.

Machine Learning Groups

C.

Custom IOA Rule Groups

D.

Custom IOC Groups

Buy Now
Questions 23

Where can you find hosts that have been offline for ten minutes or longer?

Options:

A.

Host Management

B.

Sensor Coverage Dashboard

C.

Host Groups

Buy Now
Questions 24

What happens to policy assignment when a host does not match any custom host group criteria?

Options:

A.

The last active policy remains

B.

The default policy is applied

C.

No policy is applied

D.

The most restrictive policy is applied

Buy Now
Questions 25

What prevention policy setting prevents sensor-related files, folders, and registry objects from being renamed or deleted?

Options:

A.

Host Modification Protection

B.

System Configuration Protection

C.

Sensor Tampering Protection

D.

Sensor Modification Protection

Buy Now
Questions 26

What is the highest level of protection for a prevention policy?

Options:

A.

Phase 1

B.

Phase 2

C.

Phase 3

Buy Now
Questions 27

Which report provides a filterable high-level overview of host information such as OS version, Device Type and Machine Domain, and also provides an active sensor heat map for a quick environment review?

Options:

A.

Sensor Status Report

B.

Sensor Report

C.

Sensor Overview Report

D.

Sensor Policy Daily Report

Buy Now
Questions 28

You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?

Options:

A.

Create a static group with the assignment rule criteria set to OS Type Workstation

B.

Create a dynamic group with the assignment rule criteria set to OS Type Workstation

C.

Create a static group with the assignment rule criteria for OS Version set to Windows 10

D.

Create a dynamic group with the assignment rule criteria for OS Version set to Windows 10

Buy Now
Questions 29

When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?

Options:

A.

Condition

B.

Parameter

C.

Filter

D.

Trigger Details

Buy Now
Questions 30

Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?

Options:

A.

Write an IOA rule to monitor process creation of .*\\remote\.exe

B.

Create an exclusion for remote.exe and set a workflow to email you every time the exclusion is used

C.

Write a scheduled search looking for ProcessRollup2 events for remote.exe

D.

Write an IOC for remote.exe

Buy Now
Exam Code: CCFA-200b
Exam Name: CrowdStrike Falcon Certification Program
Last Update: May 18, 2026
Questions: 0
CCFA-200b pdf

CCFA-200b PDF

$25.5  $84.99
CCFA-200b Engine

CCFA-200b Testing Engine

$30  $99.99
CCFA-200b PDF + Engine

CCFA-200b PDF + Testing Engine

$255  $850