Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

CCFA-200b CrowdStrike Falcon Certification Program Questions and Answers

Questions 4

What is the primary purpose of audit logs in Falcon?

Options:

A.

Trace file changes

B.

Track configuration changes

C.

Monitor system performance

Buy Now
Questions 5

What is the fastest way to locate inactive sensors in the Falcon console?

Options:

A.

Sort hosts by Last Seen timestamp

B.

Export all host data to CSV

C.

Filter the Host Management page to show inactive hosts

D.

Search for hosts with no Agent ID

Buy Now
Questions 6

A member of your SECOPS team is building custom scripts for RTR, but they are unable to save or share them in Falcon. What additional role do they need?

Options:

A.

Real Time Response - Active Responder

B.

Real Time Response - Administrator

C.

Workflow Author

D.

Falcon Scripts Manager

Buy Now
Questions 7

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

Options:

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

Buy Now
Questions 8

How can you search for multiple hostnames at the same time via Host Management?

Options:

A.

Enter the multiple hostnames in the Hostname filter separating each by a comma

B.

Add the Hostname filter multiple times and enter separate hostnames into each filter

C.

Enter the multiple hostnames in the Hostname filter separating each by a decimal

D.

Add the Multiple Hostnames filter and enter your list of hostnames

Buy Now
Questions 9

A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the FQDN of your patch management tools

B.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

C.

Adjust the Content Update Policies to Early Access with No Delay

D.

Create an IP group in IP Allowlist Management

Buy Now
Questions 10

Which default user role will allow you to see all analyst session details?

Options:

A.

Falcon Security Lead

B.

Real Time Response - Read-Only Analyst

C.

Falcon Administrator

D.

Real Time Response - Administrator

Buy Now
Questions 11

Which statement best describes user permissions in Falcon?

Options:

A.

Custom user role permission sets can be shared with all CrowdStrike customers globally

B.

Users can only have predefined default roles assigned to them before using a custom role

C.

User permissions can be defined by default or custom roles as needed

D.

Each Falcon permission needs to be selected when the user account is created

Buy Now
Questions 12

How are sensor updates managed and enforced across multiple hosts in Falcon?

Options:

A.

Prevention policies assigned to host groups

B.

Manual updates on each host

C.

Sensor update policies assigned to host groups

D.

Direct installation

Buy Now
Questions 13

What is true about User Accounts created by the Falcon Administrator?

Options:

A.

By default, all User Accounts are created with the Falcon Analyst role

B.

All new User Accounts are created using an employee identification number

C.

All User Accounts must start with the domain identifier and number

D.

All User Accounts must be created with an email address from the list of approved domains

Buy Now
Questions 14

Where can you find the history of the successes and failures for any Fusion SOAR workflows?

Options:

A.

Falcon UI Audit Trail

B.

Custom Alert History

C.

Workflow Audit log

D.

Workflow Execution log

Buy Now
Questions 15

After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?

Options:

A.

Falcon requires a 24-hour waiting period to apply custom policies to newly installed hosts

B.

A host-based firewall rule is preventing the custom policy from applying successfully

C.

The laptop is not a member of a host group assigned to the custom policy

D.

A prompt to apply the new prevention policy was manually declined

Buy Now
Questions 16

In order to quarantine files on the host, what prevention policy settings must be enabled?

Options:

A.

Malware Protection and Windows Anti-Malware Execution Blocking

B.

Next-Gen Antivirus Prevention sliders and “Quarantine & Security Center Registration”

C.

Malware Protection and Custom Execution Blocking

D.

Behavior-Based Threat Prevention sliders and Advanced Remediation Actions

Buy Now
Questions 17

An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

Options:

A.

75 Days

B.

60 Days

C.

90 Days

D.

45 Days

Buy Now
Questions 18

To improve the organization’s security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a new workflow from scratch, what component of the workflow must be configured first?

Options:

A.

Action

B.

Trigger

C.

Condition

D.

Workflow Name

Buy Now
Questions 19

Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?

Options:

A.

Installation and Maintenance Protection

B.

Sensor Version Control Protection

C.

Uninstall and Maintenance Protection

D.

Update and Management Protection

Buy Now
Questions 20

A Falcon Administrator is unable to initiate a Real-Time Response (RTR) session. What is the most likely cause?

Options:

A.

The domain controller is preventing the connection

B.

The host has a user logged into it

C.

There is another analyst connected into it

D.

They do not have an RTR role assigned to them

Buy Now
Questions 21

What is true about the Default Sensor Policy?

Options:

A.

It tests the sensor configuration settings before deployment

B.

It is applied automatically if no other Sensor Policies are applied

C.

It can be used to reset all sensor settings to Default

D.

It is a mechanism to deploy the oldest supported version of the Falcon Sensor

Buy Now
Questions 22

During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?

Options:

A.

Put-and-Run is not enabled in the response policy

B.

Custom Scripts is not enabled in the response policy

C.

Script-Based Execution Monitoring is not enabled in the prevention policy

D.

The responder requires the RTR Administrator role

Buy Now
Questions 23

Which report would show you an overview of the top ten most-applied policies by sensors in your environment?

Options:

A.

Scheduled reports

B.

Sensor report dashboard

C.

Executive summary

D.

Sensor policy daily report

Buy Now
Questions 24

When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?

Options:

A.

Customer ID and Integration ID

B.

Client ID and Secret

C.

Customer ID and Secret

D.

Client ID and OAuth2 ID

Buy Now
Questions 25

You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that it executes successfully?

Options:

A.

Trigger, Condition, Action

B.

Rule Type, Condition, Action

C.

Rule Type, Filter, Objective

D.

Trigger, Filter, Objective

Buy Now
Questions 26

To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group. What is required to safely and successfully test your new sensor update policy on only your test Windows servers?

Options:

A.

The new policy must be enabled and assigned a precedence that is lower when compared to the policy assigned to all Windows servers

B.

The new policy must be enabled and assigned a precedence that is higher when compared to the policy assigned to all Windows servers

C.

The new Falcon sensor version should be manually installed by you on every test Windows server before ever enabling and assigning the new policy

D.

The new Falcon sensor version should be manually uninstalled by you on every test Windows server before ever enabling and assigning the new policy

Buy Now
Questions 27

What are the three required parts of a Fusion SOAR workflow condition?

Options:

A.

Operator, value, and source

B.

Alert, action, and schedule

C.

Trigger, parameter, and alert

D.

Parameter, operator, and value

Buy Now
Questions 28

When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?

Options:

A.

Condition

B.

Parameter

C.

Filter

D.

Trigger Details

Buy Now
Questions 29

Your leadership wants controls in place for immediate action on any OverWatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?

Options:

A.

Create a Fusion SOAR workflow using the OverWatch playbook to contain the host and email the SOC team

B.

Create a Fusion SOAR workflow to contain the host and email the OverWatch team

C.

Create a Fusion SOAR workflow to trigger on an OverWatch detection and set it to block the detection

D.

Create a Fusion SOAR workflow to create a detection for OverWatch and email the SOC team

Buy Now
Questions 30

What default user role can manage API credentials?

Options:

A.

Falcon Security Lead

B.

Falcon Administrator

C.

Falcon API Manager

D.

Endpoint Manager

Buy Now
Exam Code: CCFA-200b
Exam Name: CrowdStrike Falcon Certification Program
Last Update: Jun 4, 2026
Questions: 100

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99