
CCFA-200b Practice Test Questions Updated 102 Questions
CrowdStrike CCFA-200b Dumps - Secret To Pass in First Attempt
CrowdStrike CCFA-200b Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 51
Which role allows management of quarantined files?
- A. Endpoint Manager
- B. Falcon Security Lead
- C. Falcon Analyst - Read Only
- D. Detections Exceptions Manager
Answer: B
Explanation:
The correct role is Falcon Security Lead. Falcon role guidance identifies Falcon Security Lead as a role that can manage detections, manage quarantined files, contain hosts, search events, reset user credentials, and view exclusions. Falcon Analyst - Read Only can view detections and exclusions but does not have management authority over quarantined files. Endpoint Manager is focused on sensor deployment, sensor configuration, update policies, and host group administration; it is not the role for quarantine management.
Detections Exceptions Manager is associated with exception or exclusion-style administration, not quarantined file operations. Managing quarantined files includes operational actions such as reviewing quarantined items, releasing files, undoing releases, deleting quarantined files, and potentially downloading extracted files when permitted by configuration and role. Because quarantine actions can reintroduce files to endpoints or remove evidence, Falcon assigns this capability only to roles with sufficient security operations authority. Reference topics: User Management, Default Roles, Falcon Prevent Roles, Quarantined Files.
NEW QUESTION # 52
What happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
- A. The detections for the host are removed from the console immediately
- B. All detection data for the host is deleted and the host is hidden from view
- C. New detections are disabled for 30 days
- D. Existing detections for the host remain
Answer: A
Explanation:
After clicking Disable Detections for a host, detections for that host are removed from the console immediately, and new detections do not display going forward unless detections are re-enabled. This action suppresses console detection visibility for the host; it does not uninstall the sensor or stop the sensor from operating. Existing detection data remains available in Event Search, but it is removed from the Endpoint detections console view. This distinction is important: disabling detections affects detection display and DetectionSummaryEvent behavior, not all telemetry collection or prevention policy processing. The course guide contrasts this with deleting a host, where prior detections remain visible. For Disable Detections specifically, the immediate console effect is removal of detections.
NEW QUESTION # 53
During a Windows system investigation via Real Time Response (RTR), an RTR Active Responder is unable to execute a custom powershell script for finding specific system artifacts.
What is likely restricting the responder from executing the powershell script?
- A. The responder requires the RTR Administrator role
- B. Put-and-Run is not enabled in the response policy
- C. Script-Based Execution Monitoring is not enabled in the prevention policy
- D. Custom Scripts is not enabled in the response policy
Answer: D
NEW QUESTION # 54
From the Host management page, what is the best field to filter by for Domain Controllers to obtain sensor version information?
- A. OS Version
- B. Platform
- C. Sensor Version
- D. Type
Answer: D
NEW QUESTION # 55
When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?
- A. API Client and Secret Key
- B. Access Key and Secret Key
- C. OAuth2 Token and Client Secret
- D. Integration Key and Customer ID
Answer: A
Explanation:
Third-party integrations require an API Client and Secret Key . Falcon API access is configured by creating an API client with the required scopes, then securely storing the generated client ID and secret. The integration uses those credentials to request OAuth2 tokens and interact with the Falcon APIs according to the assigned scopes. An OAuth2 token is obtained after the client credentials are created; it is not the first credential combination generated. "Access Key and Secret Key" resembles cloud provider terminology, while
"Integration Key and Customer ID" is not the standard Falcon API credential pair. The CCFA user and API management material emphasizes creating scoped API clients and protecting the secret because it is shown only at creation time.
NEW QUESTION # 56
What least privilege role should be given to a user who needs to extract files with RTR?
- A. Real Time Responder - Active Responder
- B. Falcon Investigator
- C. Falcon Security Lead
- D. Real Time Responder - Administrator
Answer: A
Explanation:
The least privilege role for extracting files with RTR is Real Time Responder - Active Responder . The Active Responder role includes the ability to use the get command to retrieve files from endpoints, along with additional response commands beyond read-only reconnaissance. The RTR Administrator role can also extract files, but it grants broader capabilities such as creating custom scripts, uploading files with put, and directly running executables, so it is not least privilege. Falcon Security Lead and Falcon Investigator are detection and investigation roles but do not provide the required RTR command authority by themselves.
CCFA role design emphasizes giving users only the permissions needed to complete the task. For file extraction, Active Responder is sufficient and appropriately scoped.
NEW QUESTION # 57
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
- A. Workflow Audit log
- B. Falcon Ul Audit Trail
- C. Custom Alert History
- D. Workflow Execution log
Answer: D
Explanation:
The place where you can find the history of the successes and failures for any Falcon Fusion workflows is the Workflow Execution log. The Workflow Execution log in the Workflow Management option allows you to view the status and results of workflow executions triggered by detection events. You can filter the log by workflow name, status, start and end time, and detection ID. You can also view the details of each execution, including the actions performed, the output received, and any errors encountered. This log can help you troubleshoot potential failures or issues with your workflows.
NEW QUESTION # 58
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
- A. Auto - N-1
- B. Specific sensor version number
- C. Auto - TEST-QA
- D. Sensor version updates off
Answer: B
Explanation:
The administrator can choose a specific sensor version number in the Sensor Update policy to manually control when the sensor version is upgraded or downgraded. This will allow the Falcon Cloud to push out sensor version changes, but only when the administrator changes the version number in the policy. The other options will either automate the sensor version updates or turn them off completely.
NEW QUESTION # 59
Your leadership wants controls in place for immediate action on any Overwatch detections.
What should you do to ensure the host is contained quickly and notifies the appropriate staff?
- A. Create a Fusion SOAR workflow to trigger on an Overwatch detection and set it to block the detection
- B. Create a Fusion SOAR workflow to contain the host and email the Overwatch team
- C. Create a Fusion SOAR workflow using the Overwatch playbook to contain the host and email the SOC team
- D. Create a Fusion SOAR workflow to create a detection for Overwatch and email the SOC team
Answer: C
NEW QUESTION # 60
Which of the following applies to Custom Blocking Prevention Policy settings?
- A. Blocklisting applies to hashes, IP addresses, and domains
- B. Hashes must be entered on the Prevention Hashes page before they can be blocked via this policy
- C. Executions blocked via hash blocklist may have partially executed prior to hash calculation process remediation may be necessary
- D. You can only blocklist hashes via the API
Answer: B
Explanation:
Falcon allows you to upload hashes from your own black or white lists. To enabled this navigate to the Configuration App, Prevention hashes window, and click on "Upload Hashes" in the upper right-hand corner. Note that you can also automate the task of importing hashes with the CrowdStrike Falcon?API.
NEW QUESTION # 61
Which of the following would give you information about inactive sensors within the Falcon console?
- A. Sensor Health
- B. Sensor Downloads
- C. Sensor Update Policies
- D. Sensor Coverage Lookup
Answer: A
NEW QUESTION # 62
A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?
- A. Create a Containment Policy that allow lists the specific IP addresses of your patch management tools
- B. Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools
- C. Remove Host containment and update the host with all patches
- D. Create a Firewall Policy that allow lists your patch management tools
Answer: A
Explanation:
Network containment isolates a host from normal network communication to prevent lateral movement and attacker-controlled access. By default, a contained host cannot reach patching infrastructure, so operating system patch jobs fail unless specific exceptions are added. The Falcon configuration point for this is the Containment Policy , where administrators allowlist specific IP addresses that contained hosts may continue to communicate with. The official guidance states that to install patches on network-contained hosts, administrators must add the IP address of the Windows Update source or patching source to the environment' s containment policy. FQDN allowlisting is not the correct answer in this context; the supported containment exception is IP-based. Removing containment would restore connectivity but would also eliminate the protective isolation during a zero-day remediation scenario. Firewall Policy is not the control that governs Falcon network containment exceptions. Reference topics: Network Containment, Containment Policy, Patch Windows Hosts, Policy Application.
NEW QUESTION # 63
What is the function of a single asterisk (*) in an ML exclusion pattern?
- A. The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path
- B. The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path
- C. The single asterisk is the insertion point for the variable list that follows the path
- D. The single asterisk is only used to start an expression, and it represents the drive letter
Answer: B
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/machine-learning The asterisk is a wildcard character that can be used in exclusion patterns to match any number of characters. However, it does not match separator characters, such as \ or /, which are used to separate portions of a file path. For example, the pattern C:\Windows\*\*.exe will match any executable file in any subfolder of the Windows folder, but not in the Windows folder itself.
NEW QUESTION # 64
You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents.
Which three items must be defined in every trigger so that it executes successfully?
- A. Rule Type, Filter, Objective
- B. Rule Type, Condition, Action
- C. Trigger, Condition, Action
- D. Trigger, Filter, Objective
Answer: C
NEW QUESTION # 65
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however, when applying the new prevention policy this group is not appearing in the list of available groups. What is the most likely issue?
- A. The new prevention policy should be enabled first
- B. Host type was not defined correctly within the prevention policy
- C. The "Servers" group already has a policy applied to it
- D. The "Servers" group must be disabled first
Answer: C
Explanation:
The most likely issue for not being able to apply a new prevention policy to the "Servers" group is that the "Servers" group already has a policy applied to it. A prevention policy is a policy that defines the prevention capabilities and settings for the Falcon sensor on a host. You can create and assign custom prevention policies to different hosts or groups in your environment. However, you can only assign one prevention policy per host or group at a time. If a host or group already has a prevention policy applied to it, you cannot apply another prevention policy to it unless you remove or replace the existing one.
NEW QUESTION # 66
When editing an existing IOA exclusion, what can NOT be edited?
- A. The hosts groups
- B. The exclusion name
- C. The IOA name
- D. All parts of the exclusion can be changed
Answer: C
Explanation:
When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as "Suspicious Process Execution - Script Interpreter Executing File". The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform. However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria.
NEW QUESTION # 67
What happens to policy assignment when a host does not match any custom host group criteria?
- A. No policy is applied
- B. The last active policy remains
- C. The most restrictive policy is applied
- D. The default policy is applied
Answer: D
Explanation:
When a host does not match a custom host group assigned to a policy, Falcon applies the applicable Default Policy . Falcon policies operate through host group assignment and precedence. A host may match one or more groups; when multiple policies apply, precedence determines which policy wins. If no custom policy assignment applies, the default policy is the fallback. The platform does not leave hosts without policy coverage, nor does it retain a previously active custom policy indefinitely once the host no longer qualifies. It also does not automatically choose the most restrictive policy unless that policy is assigned and has the highest precedence. This default-policy behavior is central to safe policy design in CCFA: administrators must review default policy settings because unassigned hosts inherit them.
NEW QUESTION # 68
Which role is required to manage groups and policies in Falcon?
- A. Falcon Host Administrator
- B. Falcon Host Security Lead
- C. Falcon Host Analyst
- D. Prevention Hashes Manager
Answer: A
Explanation:
The Falcon Host Administrator role is required to manage groups and policies in Falcon. This role allows users to create, edit and delete groups and policies, as well as assign them to hosts. The other roles do not have this capability. Reference: [CrowdStrike Falcon User Guide], page 17.
NEW QUESTION # 69
What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?
- A. Hosts Overview
- B. Activity Overview
- C. Sensor Health
- D. Support and resources
Answer: C
Explanation:
The correct page is Sensor Health . The Sensor Health dashboard is designed to show Falcon sensor operational status across the environment and help administrators identify hosts running unsupported sensor versions, unsupported operating system versions, incorrect configurations, connectivity problems, and RFM conditions. The official guidance states that the Sensor Health dashboard includes information about "hosts that entered RFM each day" and clarifies that this shows hosts newly entering Reduced Functionality Mode, not the total number of hosts currently in RFM. This distinction matters because Sensor Health is used to track newly emerging sensor health issues over time, while Host Management can be used to filter for the current list of hosts in RFM. Hosts Overview and Activity Overview do not provide this specific daily RFM count. Support and resources is a navigation area, not the sensor health reporting dashboard. Reference topics:
Dashboards and Reports, Sensor Health Dashboard, Reduced Functionality Mode, Sensor Operational Status.
NEW QUESTION # 70
The alignment of a particular prevention policy to one or more host groups can be completed in which of the following locations within Falcon?
- A. Policy alignment is configured in the "Host Management" section in the Hosts application
- B. Policy alignment is configured in the General Settings section under the Configuration menu
- C. Policy alignment is configured in each policy in the "Assigned Host Groups" tab
- D. Policy alignment is configured only once during the initial creation of the policy in the "Create New Policy" pop-up window
Answer: C
Explanation:
The alignment of a particular prevention policy to one or more host groups can be completed in each policy in the "Assigned Host Groups" tab. This tab allows the administrator to select which host groups will use the policy, as well as view the number of hosts and sensors assigned to each group. The other options are either incorrect or not available.
NEW QUESTION # 71
......
CrowdStrike CCFA-200b Exam Dumps [2026] Practice Valid Exam Dumps Question: https://www.free4dump.com/CCFA-200b-braindumps-torrent.html
CCFA-200b Dumps - Grab Out For [NEW-2026] CrowdStrike Exam: https://drive.google.com/open?id=1Fy8ZCvDhngPZl5IENDRKImZzuLy-XF5O