Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CrowdStrike Certified Falcon Administrator CCFA-200b Exam Questions

Page: 1 / 11 Total 153 questions

Want more questions? Get Premium Access.

Question 1

Where in the console can you find a list of all hosts in your environment that are in Reduced Functionality Mode (RFM)?

Correct Answer: B. Host Management > Filter for RFM
Explanation:

The place in the console where you can find a list of all hosts in your environment that are in Reduced Functionality Mode (RFM) is Host Management > Filter for RFM. The Host Management page allows you to view and manage all hosts in your environment that have Falcon sensors installed. You can use the filter bar to filter hosts by various attributes, such as status, platform, type, or group. You can also filter hosts by health events, such as RFM, which is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure.By filtering for RFM, you can see a list of all hosts that are in this mode1.


Question 2

What information does the API Audit Trail Report provide?

Correct Answer: C. A list of actions taken via Falcon OAuth2-based APIs
Explanation:

The information that the API Audit Trail Report provides is a list of actions taken via Falcon OAuth2-based APIs. The API Audit Trail Report allows you to view and audit the activity and usage of the Falcon APIs by different API clients and users in your organization.You can use this report to monitor who accessed what data, when, and how via the Falcon APIs2.


Question 3

How do you disable all detections for a host?

Correct Answer: D. In Host Management, select the host and then choose the option to Disable Detections
Explanation:

The administrator can disable all detections for a host by selecting the host and then choosing the option to Disable Detections in the Host Management page. This will prevent the host from sending any detection events to the Falcon Cloud. The other options are either incorrect or not available. Reference: [CrowdStrike Falcon User Guide], page 32.


Question 4

What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?

Correct Answer: B. Trigger, condition(s) and action(s)
Explanation:

The model that is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform is trigger, condition(s) and action(s). This model allows you to specify what event will trigger the workflow, what condition(s) must be met for the workflow to execute, and what action(s) will be performed by the workflow. The other options are either incorrect or not related to creating workflows. Reference:CrowdStrike Falcon User Guide, page 56.


Question 5

To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

Correct Answer: A. Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead
Explanation:

IOC management only allows 'Detect only' and 'No Action' among the possible actions. Therefore, it cannot be used to block based on IPs or domains. Custom IOA Rule groups allow to create rule types based on Network Connection (configuring a remote IP address) and domains, and gives the options to 'Monitor', 'Detect' and 'Kill Process', being the late one the closest to 'block'.


Question 6

Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?

Correct Answer: A. \Program Files\My Program\My Files\*
Explanation:

The exclusion pattern that will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe is \Program Files\My Program\My Files*. This pattern will match any file under the My Files folder, including program.exe, and exclude them from detections. The other patterns are either incorrect or too broad to prevent detections on this specific file. Reference: [CrowdStrike Falcon User Guide], page 37.


Question 7

When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?

Correct Answer: D. Hostname
Explanation:

When performing targeted filtering for a host on the Host Management Page, the filter bar attribute that is not case-sensitive is Hostname. The Hostname attribute allows you to filter hosts by their computer name or DNS name. The Hostname filter is not case-sensitive, meaning that it will match hosts regardless of the capitalization of their names.For example, filtering by hostname=DESKTOP-1234 will match hosts with names such as DESKTOP-1234, desktop-1234, or Desktop-12342.


Question 8

Why is the ability to disable detections helpful?

Correct Answer: A. It gives users the ability to set up hosts to test detections and later remove them from the console
Explanation:

'Disable Detections. This is helpful for users who want to set up hosts to test detections in the Falcon console and who later want to remove those old test detections from the'


Question 9

What is the purpose of precedence with respect to the Sensor Update policy?

Correct Answer: B. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
Explanation:

The purpose of precedence with respect to the Sensor Update policy is that hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number). This means that if a host belongs to more than one group that has different Sensor Update policies assigned, it will use the policy that has the highest precedence (lowest number) among them. The other options are either incorrect or not related to precedence. Reference:CrowdStrike Falcon User Guide, page 38.


Question 10

Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?

Correct Answer: B. Machine Learning Prevention Monitoring
Explanation:

The Machine Learning Prevention Monitoring report in the Prevention Policy Management option allows you to monitor the impact of machine learning (ML) prevention settings on your environment. You can view the number of ML detections and preventions by severity, policy, and host group. You can also drill down into specific events and hosts to see more details.This report can help you determine the appropriate ML levels to set in a prevention policy based on your risk tolerance and security posture1.


Question 11

What is the purpose of using groups with Sensor Update policies in CrowdStrike Falcon?

Correct Answer: D. To allow the controlled assignment of sensor versions onto specific hosts
Explanation:

The purpose of using groups with Sensor Update policies in CrowdStrike Falcon is to allow the controlled assignment of sensor versions onto specific hosts. This allows users to manage the sensor updates for different hosts based on their needs and preferences, such as testing, staging or production. The other options are either incorrect or not related to using groups with Sensor Update policies. Reference: [CrowdStrike Falcon User Guide], page 38.


Question 12

What is the purpose of the Machine-Learning Prevention Monitoring Report?

Correct Answer: D. It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
Explanation:

Machine-Learning Prevention Monitoring dashboard: Use this dashboard to view malware that would have been blocked in your environment over the selected timeframe based on different Machine Learning Prevention settings (Cautious, Moderate, Aggressive or Extra Aggressive).


Question 13

You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?

Correct Answer: B. Using IOC Management, add the hash of the binary in question and set the action to 'Allow'
Explanation:

to match any number of characters including none while not matching beyond path separators (\ or /) and double asterisks are used to recursively match zero or more directories that fall under the current directory.


Question 14

How many days will an inactive host remain visible within the Host Management or Trash pages?

Correct Answer: C. 90 days
Explanation:

An inactive host will remain visible within the Host Management or Trash pages for 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform.You can restore an inactive host from the Trash page if it becomes active again within 90 days1.


Question 15

An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?

Correct Answer: C. There is no limit and exclusions can be applied to any or all groups
Explanation:

An exclusion is a rule that tells the Falcon platform to ignore certain files, folders, processes, or registry keys when performing prevention or detection actions. An administrator can create an exclusion and apply it to one or more groups of hosts, or to all hosts in the organization. For example, an administrator can create an exclusion for a legitimate application that is causing false positives and apply it to the group of hosts that are running that application.