
Updated Apr-2026 Test Engine to Practice CCFA-200b Dumps & Practice Exam
Dumps Collection CCFA-200b Test Engine Dumps Training With 255 Questions
CrowdStrike CCFA-200b Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 134
As a Falcon Administrator, you would like to tune your Prevention Policies and compare the number of detections that would have resulted in the last 30 days depending on which detection level was used (Cautious, Moderate, Aggressive or Extra Aggressive).
Which audit logs would best help you evaluate the appropriate setting to use?
- A. Machine-learning prevention monitoring
- B. Prevention policy
- C. Prevention policy debug
- D. Policy efficacy monitoring
Answer: A
NEW QUESTION # 135
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
- A. Install the Falcon package, use falconctl to license the sensor, approve the system extension, grant the sensor Full Disk Access
- B. Grant the Falcon Package Full Disk Access, install the Falcon package, use falconctl to license the sensor
- C. Grant the Falcon Package Full Disk Access, install the Falcon package, load the Falcon Sensor with the command 'falconctl stats'
- D. Install the Falcon package passing it the installation token in the command line
Answer: A
Explanation:
The option that best describes the general process for installation of the Falcon Sensor on MacOS is to install the Falcon package, use falconctl to license the sensor, approve the system extension, grant the sensor Full Disk Access. The Falcon package contains the sensor binary and the kernel extension, which can be installed by double-clicking on it or using a command-line tool such as installer. The falconctl tool is a command-line utility that allows you to configure and manage the sensor on MacOS systems. You can use falconctl to license the sensor by providing your Customer ID (CID) and optionally your Sensor Group ID (SGID). After licensing the sensor, you need to approve the system extension in the Security & Privacy settings of your system preferences, which will require a restart. Finally, you need to grant the sensor Full Disk Access in the Privacy settings of your system preferences, which will allow the sensor to monitor and protect your files and folders.
NEW QUESTION # 136
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
- A. Under Host setup and management, choose the Host Management page. Set the group filter to
"Inactive Sensors" - B. Under Host setup and management > Managed endpoints > Inactive Sensors. Change the time range to 30 days
- C. Under Host setup and management, choose the Disabled Sensors Report. Change the time range to 30 days
- D. Under Dashboards and reports, choose the Sensor Report. Set the "Last Seen" dropdown to 30 days and reference the Inactive Sensors widget
Answer: B
Explanation:
The administrator can find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days by going to Host setup and management > Managed endpoints > Inactive Sensors. Then, change the time range to 30 days. This will show the host name, last seen date, sensor version and group name for each inactive host. The other options are either incorrect or not available.
NEW QUESTION # 137
Which of the following applies to Custom Blocking Prevention Policy settings?
- A. Blocklisting applies to hashes, IP addresses, and domains
- B. Executions blocked via hash blocklist may have partially executed prior to hash calculation process remediation may be necessary
- C. You can only blocklist hashes via the API
- D. Hashes must be entered on the Prevention Hashes page before they can be blocked via this policy
Answer: D
Explanation:
Falcon allows you to upload hashes from your own black or white lists. To enabled this navigate to the Configuration App, Prevention hashes window, and click on "Upload Hashes" in the upper right-hand corner. Note that you can also automate the task of importing hashes with the CrowdStrike Falcon?API.
NEW QUESTION # 138
You need to create a rule to block all process executions of Telegram in your environment.
Which custom IOA rule configuration would accomplish this?
- A. Custom IOA rule configuration cannot block non-malicious binaries from executing
- B. Custom IOA rule set to Monitor on an Image Filename of .*Telegram.*
- C. Custom IOA rule set to Block Execution on an Image Filename of .*Telegram.*
- D. Custom IOA rule set to Detect on an Image Filename of .*Telegram.*
Answer: C
NEW QUESTION # 139
If you are not able to update your Falcon sensors on a regular basis, what is the maximum recommended aging period before updating your sensors?
- A. 7 days
- B. 60 days
- C. 90 days
- D. There is no maximum aging period
Answer: C
NEW QUESTION # 140
Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
- A. FileSystem Visibility
- B. Script-based Execution Monitoring
- C. Suspicious Scripts and Commands
- D. Engine (Full Visibility)
Answer: B
Explanation:
The prevention policy setting that monitors contents of scripts and shells for execution of malicious content on compatible operating systems is Script-based Execution Monitoring. Script- based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. You can enable or disable Script- based Execution Monitoring in the Prevention Policy for Windows hosts.
NEW QUESTION # 141
What default roles can view, create, and edit workflows?
- A. Falcon Administrator, Falcon Security Lead, Workflow Author
- B. Falcon Administrator, Workflow Author
- C. Falcon Administrator, Falcon Security Lead
- D. Falcon Administrator, Workflow Author, Falcon Security Lead, Falcon Investigator
Answer: A
NEW QUESTION # 142
You are tasked with creating a group for hosts running Windows 10.
What kind of group should you create to make sure all applicable hosts are included in your environment?
- A. Create a dynamic group with the assignment rule criteria for OS Version set to Windows 10
- B. Create a dynamic group with the assignment rule criteria set to OS Type Workstation
- C. Create a static group with the assignment rule criteria set to OS Type Workstation
- D. Create a static group with the assignment rule criteria for OS Version set to Windows 10
Answer: A
NEW QUESTION # 143
What could cause your Windows host to be in Reduced Functionality Mode (RFM)?
- A. A misconfiguration in your prevention policy
- B. A sensor update policy was misconfigured
- C. Crowdstrike has not certified the latest Windows update
- D. The host lost internet connectivity
Answer: C
NEW QUESTION # 144
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
- A. *baddomain\. xyz|baddomain\. xyz. *
- B. Custom IOA rules cannot be created for domains
- C. **baddomain\. xyz|baddomain\. xyz**
- D. *\.baddomain\.xyz|baddomain\. xyz
Answer: D
Explanation:
The syntax that would be best for detecting or preventing on all subdomains as well is
*.baddomain.xyz|baddomain. xyz. This syntax will match any domain that ends with .baddomain.xyz or is exactly baddomain.xyz. The * wildcard will match any characters before the dot, and the | operator will match either side of the expression. This syntax can be used in a Custom IOC or a Custom IOA rule to detect or prevent network connections to malicious domains.
NEW QUESTION # 145
What internet domain needs to be added to any required allowlists to allow sensors to communicate with the CrowdStrike Cloud?
- A. cloudsink.net
- B. csfalcon.net
- C. cloudprotect-cs.net
- D. falconcloud.net
Answer: A
NEW QUESTION # 146
You are deploying the Falcon sensor to a total of 500 hosts. Hosts in an Organizational Unit (OU) will need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter.
What is the best way to create a host group for this OU?
- A. Create a dynamic group with an assignment rule that filters for the OU
- B. Create a static group with from list of all 500 host names.
- C. Create a static group with from list of host names in the OU
- D. Create a dynamic group with an assignment rule that excludes the OU
Answer: A
NEW QUESTION # 147
Which prevention policy setting monitors contents of scripts and shells for execution of malicious content?
- A. FileSystem Visibility
- B. Script-based Execution Monitoring
- C. Suspicious Scripts and Commands
- D. Engine (Full Visibility)
Answer: B
NEW QUESTION # 148
The Logon Activities Report includes all of the following information for a particular user EXCEPT
__________.
- A. the account type for the user (e.g. Domain Administrator, Local User)
- B. all hosts the user logged into
- C. the last time the user's password was set
- D. the logon type (e.g. interactive, service)
Answer: B
Explanation:
Checked in console, it returns only the last machine where the user logged on, so it will not return all the machines that the user was logged on in the desired search.
NEW QUESTION # 149
When deploying the Falcon Sensor alongside an existing security solution, you enable the Quarantine prevention setting in Falcon. What is the recommended configuration for both solutions?
- A. Disable or remove the other AV solution and configure ODS Cloud Anti-Malware prevention in Falcon to Moderate or higher
- B. Disable or remove the other AV solution and configure NGAV Cloud Machine Learning prevention in Falcon to Extra-Aggressive
- C. Disable or remove the other AV solution and configure NGAV Sensor Machine Learning prevention in Falcon to Moderate or higher
- D. Disable or remove the other AV solution and configure NGAV Sensor Machine Learning prevention in Falcon to Cautious
Answer: C
NEW QUESTION # 150
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?
- A. There is no limit and exclusions can be applied to any or all groups
- B. There is a limit of three groups of hosts applied to any exclusion
- C. Each exclusion can be aligned to only one group of hosts
- D. File exclusions are not aligned to groups or hosts
Answer: A
Explanation:
An exclusion is a rule that tells the Falcon platform to ignore certain files, folders, processes, or registry keys when performing prevention or detection actions. An administrator can create an exclusion and apply it to one or more groups of hosts, or to all hosts in the organization. For example, an administrator can create an exclusion for a legitimate application that is causing false positives and apply it to the group of hosts that are running that application.
NEW QUESTION # 151
You will be testing detections with pentest and security tooling on your host.
How can a workflow be created to automatically assign any detection related to your pentest to yourself in real time?
- A. Create an Event trigger workflow that triggers on an EPP Detection with an action to assign the detection to yourself
- B. Create a workflow to disable detections for your host until testing is done
- C. Create an Event trigger workflow that triggers on an EPP Detection with conditions looking for the desired hostname. The Action will then assign the detection to yourself.
- D. Create a scheduled workflow to run once a day that triggers on an EPP Detection with conditions looking for the desired hostname. The Action will then assign the detection to yourself.
Answer: C
NEW QUESTION # 152
You have 100 hashes that have been prohibited by management and need to be blocked within your organization.
Using Falcon, what is the best way to accomplish this?
- A. Navigate to Configure > Prevention policies. Inside this dashboard, add an IOC Policy. Add the list of hashes as CSV file. Set the action to "Block." Verify the option for Custom Execution Blocking is active.
- B. Navigate to Configure > IOC Management. Inside this dashboard, add a custom IOAdd the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.
- C. Navigate to Configure > IOC Management. Inside this dashboard, add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.
- D. Navigate to Configure > Prevention policies. Inside this dashboard, add an IOC Policy. Add the list of hashes as a CSV file. Set the action to "Block and Alert." Verify the option for Custom Blocking inside Execution Blocking is active.
Answer: B
NEW QUESTION # 153
......
CrowdStrike CCFA-200b Dumps Cover Real Exam Questions: https://simplilearn.actual4labs.com/CrowdStrike/CCFA-200b-actual-exam-dumps.html