Pre-Summer Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

CCFA-200b CrowdStrike Falcon Certification Program Questions and Answers

Questions 4

You are assigning sensor group tags during installation. What is the maximum allowed length of all tags?

Options:

A.

237 characters

B.

256 characters

C.

50 characters

D.

100 characters

Buy Now
Questions 5

You are deploying the Falcon sensor to 500 hosts. Hosts in an Organizational Unit need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter. What is the best way to create a host group for this OU?

Options:

A.

Create a Dynamic Group targeting Windows 10 OS in the domain

B.

Create a dynamic group with an assignment rule that excludes the OU

C.

Create a dynamic group with an assignment rule that filters for the OU

Buy Now
Questions 6

What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?

Options:

A.

Hosts Overview

B.

Sensor Health

C.

Activity Overview

D.

Support and resources

Buy Now
Questions 7

When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?

Options:

A.

Access Key and Secret Key

B.

Integration Key and Customer ID

C.

API Client and Secret Key

D.

OAuth2 Token and Client Secret

Buy Now
Questions 8

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

Options:

A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

B.

Implement an SVE on the particular host

C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done

D.

Use Real Time Response to kill the offending process on the server

Buy Now
Questions 9

Your security team is noticing that certain privacy-sensitive information such as the URL, HTTP Header and POST bodies are missing from HTTP related detections. What is likely the cause for this?

Options:

A.

The prevention policy was configured to have an aggressive prevention setting, but only a cautious detection setting

B.

The prevention policy has been configured to redact HTTP detection details

C.

The network perimeter firewall blocked the HTTP connection attempts so there was nothing for Falcon to detect

D.

The prevention policy was never configured to generate HTTP detections

Buy Now
Questions 10

When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?

Options:

A.

Condition

B.

Parameter

C.

Filter

D.

Trigger Details

Buy Now
Questions 11

You will be testing detections with pentest and security tooling on your host. How can a workflow be created to automatically assign any detection related to your pentest to yourself in real time?

Options:

A.

Create an Event trigger workflow that triggers on an EPP Detection with an action to assign the detection to yourself

B.

Create an Event trigger workflow that triggers on an EPP Detection with conditions looking for the desired hostname

C.

Create an alert on usage of the tools and assign the alerts to you automatically via workflow

D.

Create an IOC for the host to trigger associated detections and assign them to you via workflow

Buy Now
Questions 12

What action should you take to securely allow operating system update processes to occur during network containment?

Options:

A.

Ensure all internal network IPs are allowed

B.

Add IPs of update sources to the Containment policy

C.

Add sources to the Host Firewall policy

D.

Remove network containment to allow access

Buy Now
Questions 13

What default user role can manage API credentials?

Options:

A.

Falcon Security Lead

B.

Falcon Administrator

C.

Falcon API Manager

D.

Endpoint Manager

Buy Now
Questions 14

You want to add an additional layer of security to high-risk Real Time Response commands for your environment. Where do you configure MFA for RTR within the UI?

Options:

A.

General settings

B.

Notifications

C.

Response policies

D.

Containment policy

Buy Now
Questions 15

Using Host setup and management inside the Falcon Console, how can you display sensors in Reduced Functionality Mode?

Options:

A.

From Host management, filter for RFM

B.

From Host status, filter for RFM

C.

From Sensor health, sort using the column heading Sensor status

D.

From Sensor status, click on the widget RFM

Buy Now
Questions 16

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?

Options:

A.

Create an exclusion for the felix.dll file

B.

Create an IOA exclusion for C:\Users\Bob\DevCode\felix.dll

C.

Create a separate Host Group for development machines and apply a less restrictive policy

D.

Create a Custom IOC and set it to Allow for C:\Users\Bob\DevCode\felix.dll

Buy Now
Questions 17

How can you search for multiple hostnames at the same time via Host Management?

Options:

A.

Enter the multiple hostnames in the Hostname filter separating each by a comma

B.

Add the Hostname filter multiple times and enter separate hostnames into each filter

C.

Enter the multiple hostnames in the Hostname filter separating each by a decimal

D.

Add the Multiple Hostnames filter and enter your list of hostnames

Buy Now
Questions 18

When installing the Falcon Sensor manually on Microsoft Windows, where is the installation log data stored?

Options:

A.

%LOCALAPPDATA%\Temp

B.

%SYSTEMROOT%\Temp

C.

%SYSTEMROOT%\Logs

D.

%LOCALAPPDATA%\Logs

Buy Now
Questions 19

When using Microsoft Windows, what command verifies that a Falcon Sensor is running?

Options:

A.

cswindiag.exe -status

B.

sc.exe query csagent

C.

netstat.exe -f

D.

sc.exe query falcon

Buy Now
Questions 20

What are the two automated triggers that cause a Fusion SOAR workflow to run?

Options:

A.

Incident and detections triggers

B.

Event and scheduled triggers

C.

Condition and action triggers

D.

Event and action triggers

Buy Now
Questions 21

After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?

Options:

A.

The rule must be manually triggered

B.

Hosts must be individually selected to apply to the rule

C.

The rule group must be assigned to a prevention policy

Buy Now
Questions 22

What is the fastest way to locate inactive sensors in the Falcon console?

Options:

A.

Sort hosts by Last Seen timestamp

B.

Export all host data to CSV

C.

Filter the Host Management page to show inactive hosts

D.

Search for hosts with no Agent ID

Buy Now
Questions 23

Where can you find the history of the successes and failures for any Fusion SOAR workflows?

Options:

A.

Falcon UI Audit Trail

B.

Custom Alert History

C.

Workflow Audit log

D.

Workflow Execution log

Buy Now
Questions 24

In order to receive the most stable sensor updates, what level of automatic sensor updates should be applied to a host?

Options:

A.

Auto-N-2

B.

Auto-N-1

C.

Pinned sensor version

D.

Auto-Latest

Buy Now
Questions 25

Which report provides a filterable high-level overview of host information such as OS version, Device Type and Machine Domain, and also provides an active sensor heat map for a quick environment review?

Options:

A.

Sensor Status Report

B.

Sensor Report

C.

Sensor Overview Report

D.

Sensor Policy Daily Report

Buy Now
Questions 26

What is true about User Accounts created by the Falcon Administrator?

Options:

A.

By default, all User Accounts are created with the Falcon Analyst role

B.

All new User Accounts are created using an employee identification number

C.

All User Accounts must start with the domain identifier and number

D.

All User Accounts must be created with an email address from the list of approved domains

Buy Now
Questions 27

How are sensor updates managed and enforced across multiple hosts in Falcon?

Options:

A.

Prevention policies assigned to host groups

B.

Manual updates on each host

C.

Sensor update policies assigned to host groups

D.

Direct installation

Buy Now
Questions 28

You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?

Options:

A.

Create a static group with the assignment rule criteria set to OS Type Workstation

B.

Create a dynamic group with the assignment rule criteria set to OS Type Workstation

C.

Create a static group with the assignment rule criteria for OS Version set to Windows 10

D.

Create a dynamic group with the assignment rule criteria for OS Version set to Windows 10

Buy Now
Questions 29

To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group. What is required to safely and successfully test your new sensor update policy on only your test Windows servers?

Options:

A.

The new policy must be enabled and assigned a precedence that is lower when compared to the policy assigned to all Windows servers

B.

The new policy must be enabled and assigned a precedence that is higher when compared to the policy assigned to all Windows servers

C.

The new Falcon sensor version should be manually installed by you on every test Windows server before ever enabling and assigning the new policy

D.

The new Falcon sensor version should be manually uninstalled by you on every test Windows server before ever enabling and assigning the new policy

Buy Now
Questions 30

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

Options:

A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled

B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console

C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console

D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon

Buy Now
Exam Code: CCFA-200b
Exam Name: CrowdStrike Falcon Certification Program
Last Update: May 27, 2026
Questions: 0
CCFA-200b pdf

CCFA-200b PDF

$25.5  $84.99
CCFA-200b Engine

CCFA-200b Testing Engine

$30  $99.99
CCFA-200b PDF + Engine

CCFA-200b PDF + Testing Engine

$255  $850