
Latest [Mar 21, 2026] Real CrowdStrike CCFA-200b Exam Dumps Questions
CCFA-200b Dumps To Pass CrowdStrike Certified Falcon Administrator Exam in One Day (Updated 255 Questions)
CrowdStrike CCFA-200b Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 23
When creating a machine learning exclusion with glob syntax, what are the three items you can target for exclusion?
- A. Triggers, actions or alerts
- B. Parameters, operators, or values
- C. Drive letters, directories, or patterns
- D. File path, name, or type (extension)
Answer: D
NEW QUESTION # 24
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe.
How would you trigger a detection for review of any process named remote.exe?
- A. Create an exclusion for remote.exe and set a workflow to email you every time the exclusion is used
- B. Assign an aggressive detection level machine-learning prevention policy to the applicable hosts
- C. Write a scheduled search looking for ProcessRollup2 events for remote.exe
- D. Write an IOA rule to monitor process creation of .*\\remote\.exe
Answer: D
NEW QUESTION # 25
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
- A. Engine (Full Visibility)
- B. Script-based Execution Monitoring
- C. Interpreter-Only
- D. Additional User Mode Data
Answer: B
Explanation:
Turn on the Script-Based Execution Monitoring prevention policy setting to enable the "Falcon sensor to monitor the contents of scripts and shells that are popular mechanisms for executing malicious code on hosts. This setting does not kill or block scripts." Scripting languages:
Excel 4.0 macros
JScript
VBA Macros
VBScript
The Sensor Visibility setting that should be turned on within the Prevention policy settings to monitor suspicious VBA macros is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems. The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. VBA (Visual Basic for Applications) is a scripting language that can be embedded in Microsoft Office documents, such as Word or Excel. VBA macros can be used to automate tasks or perform actions within the documents, but they can also be abused by attackers to deliver malware or execute malicious code. Script-based Execution Monitoring can help detect and prevent such attacks by monitoring the contents of VBA macros for execution of malicious content.
NEW QUESTION # 26
Once an exclusion is saved, what can be edited in the future?
- A. Only the options to "Detect/Block" and/or "File Extraction" can be changed
- B. The exclusion pattern cannot be changed
- C. Only the selected groups and hosts to which the exclusion is applied can be changed
- D. All parts of the exclusion can be changed
Answer: D
Explanation:
Once an exclusion is saved, all parts of the exclusion can be changed in the future. The administrator can edit an existing exclusion by selecting it from the Exclusions page and modifying any of its fields, such as pattern, type, option, group or host. The other options are either incorrect or not true of editing exclusions.
NEW QUESTION # 27
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
- A. Custom IOC Groups
- B. Custom IOA Rule Groups
- C. Operating System Groups
- D. Enterprise Groups
Answer: B
Explanation:
Prevention Policies are created based on the OS (Windows, MAC and Linux policies). Once a prevention policy is created, three options appear on top: Settings, Assigned Host Groups and Assigned Custom IOAS (tested on Crowdstrike). Therefore, Host Groups and Custom IOAS are the two different types of groups a prevention policy can be aligned to.
NEW QUESTION # 28
What is the best way to write an ML exclusion for any executable file at "C:\Program Files\Software\"?
- A. You cannot. You must list a specific file in an exclusion rule
- B. Program Files\Software\.*
- C. Program Files\Software\**
- D. Program Files\Software\*.exe
Answer: D
NEW QUESTION # 29
What are custom alerts based on?
- A. User defined Splunk queries
- B. Custom workflows
- C. Custom event based triggers
- D. Predefined alert templates
Answer: D
Explanation:
Scheduling a Custom Alert for your environment consists of three steps: choosing the template you'd like to configure, previewing the search results, then scheduling the alert. Use Custom Alerts to configure email alerts using predefined templates so you're notified about specific activity in your environment. When an alert runs and finds results, it sends an email to specified recipients instead of generating a new detection. Custom Alerts let you set up email alerts based on predefined templates that cover a wide range of topics including Real Time Response session initiation, host containment, OS security settings, and more that are not yet covered by notification workflows.
NEW QUESTION # 30
Which of the following is a valid step when troubleshooting sensor installation failure?
- A. Disable SSL and TLS on the host
- B. Enable the Windows firewall
- C. Delete any available application crash log files
- D. Confirm all required services are running on the system
Answer: D
Explanation:
A valid step when troubleshooting sensor installation failure is to confirm all required services are running on the system. This can help identify if there are any issues with the sensor service, the Windows Management Instrumentation service, or the Windows Remote Management service, which are required for the sensor to function properly. The other options are either incorrect or not helpful for troubleshooting sensor installation failure.
NEW QUESTION # 31
What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
- A. The detections for the host are removed from the console immediately and no new detections will display in the console going forward
- B. Existing detections for the host remain, but no new detections will display in the console going forward
- C. You cannot disable detections for a host
- D. Preventions will be disabled for the host
Answer: A
Explanation:
The option that best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page is that the detections for the host are removed from the console immediately and no new detections will display in the console going forward. The "Disable Detections" feature allows you to enable or disable the detection and prevention capabilities of the Falcon sensor on a specific host. When you disable detections for a host, the sensor will stop sending any detection or prevention events to the Falcon console, and any existing events for that host will be removed from the console. When you enable detections for a host, the sensor will resume sending any new detection or prevention events to the Falcon console, but any previous events for that host will not be restored to the console.
NEW QUESTION # 32
To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group.
What is required to safely and successfully test your new sensor update policy on only your test Windows servers?
- A. The new Falcon sensor version should be manually installed by you on every test Windows server before ever enabling and assigning the new policy
- B. The new policy must be enabled and assigned a precedence that is lower when compared to the policy assigned to all Windows servers
- C. The new policy must be enabled and assigned a precedence that is higher when compared to the policy assigned to all Windows servers
- D. The new Falcon sensor version should be manually uninstalled by you on every test Windows server before ever enabling and assigning the new policy
Answer: C
NEW QUESTION # 33
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?
- A. Configure a Real Time Response policy allowlist with the specific IP addresses
- B. Configure the Host firewall to allowlist the specific IP addresses
- C. Configure a Containment Policy with the entire internal IP CIDR block
- D. Configure a Containment Policy with the specific IP addresses
Answer: D
Explanation:
While a host is Network contained, the administrator can allow the host to access internal network resources on specific IP addresses to perform patching and remediation by configuring a Containment Policy with the specific IP addresses. This policy allows users to specify which ports, protocols and IP addresses are allowed or blocked during network containment. The other options are either incorrect or not related to network containment.
NEW QUESTION # 34
In order to quarantine files on the host, what prevention policy settings must be enabled?
- A. Malware Protection and Windows Anti-Malware Execution Blocking must be enabled
- B. Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" must be enabled
- C. Behavior-Based Threat Prevention sliders and Advanced Remediation Actions must be enabled
- D. Malware Protection and Custom Execution Blocking must be enabled
Answer: B
Explanation:
In order to quarantine files on the host, the administrator must enable the Next-Gen Antivirus Prevention sliders and "Quarantine & Security Center Registration" in the prevention policy settings. This will allow Falcon to quarantine malicious files and register them with Windows Security Center. The other options are either incorrect or not sufficient to enable quarantine.
NEW QUESTION # 35
You are tasked with creating a "Workstations" host group to encompass ALL workstations in your environment.
Which dynamic grouping criteria would best accomplish this task?
- A. Platform: Windows
- B. Type: Workstation
- C. Site: Workstation
- D. Grouping Tags: Workstation
Answer: B
NEW QUESTION # 36
What kind of hosts can be contained in Falcon?
- A. Any host running the Falcon sensor
- B. Only Windows and Linux hosts running the Falcon sensor
- C. Only Windows hosts running the Falcon sensor
- D. Only Windows and MacOS hosts running the Falcon sensor
Answer: A
NEW QUESTION # 37
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?
- A. The API client secret cannot be retrieved after it has been created
- B. Enable the Client Secret column to reveal the API client secret
- C. The API client secret can be viewed from the Edit API client pop-up box
- D. Re-create the API client using the exact name to see the API client secret
Answer: A
Explanation:
The API client secret cannot be retrieved after it has been created. The secret is only displayed once when the API client is created, and it cannot be viewed or edited later. Therefore, it is important to save the secret securely and use it along with the client ID to authenticate the API client. The other options are either incorrect or not possible.
NEW QUESTION # 38
What is the earliest version of Windows Server that a Sensor is compatible with?
- A. Server 2008 R2 SP1
- B. Server 2012
- C. Server 2003
- D. Server 2008
Answer: A
NEW QUESTION # 39
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
- A. PowerShell
- B. Deep packet inspection
- C. Linux Sub-System
- D. Windows Proxy
Answer: B
Explanation:
The option that should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly is deep packet inspection. Deep packet inspection is a network configuration that inspects and modifies the data packets that pass through a firewall. Deep packet inspection may interfere with the sensor's certificate validation, which is a feature that verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. If the certificate validation fails, the sensor will reject the connection and generate an error.
NEW QUESTION # 40
To improve the organization's security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon.
When creating a new workflow from scratch, what component of the workflow must be configured first?
- A. Trigger
- B. Workflow Name
- C. Condition
- D. Action
Answer: A
NEW QUESTION # 41
On the Host management page which filter could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform?
- A. Platform
- B. Hostname
- C. Status
- D. Type
Answer: D
Explanation:
The filter that could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform on the Host Management page is Type. The Type filter allows you to filter hosts by their device type, such as workstation, server, or domain controller. The device type is assigned to each host based on their Active Directory domain structure. You can use the Type filter to quickly identify all hosts that have the workstation type assigned in their domain.
NEW QUESTION # 42
When deploying the Falcon Sensor alongside an existing security solution, you enable the Quarantine prevention setting in Falcon. What is the recommended configuration for both solutions?
- A. Disable or remove the other AV solution and configure NGAV Sensor Machine Learning prevention in Falcon to Moderate or higher
- B. Disable or remove the other AV solution and configure ODS Cloud Anti-Malware prevention in Falcon to Moderate or higher
- C. Disable or remove the other AV solution and configure NGAV Sensor Machine Learning prevention in Falcon to Cautious
- D. Disable or remove the other AV solution and configure NGAV Cloud Machine Learning prevention in Falcon to Extra-Aggressive
Answer: A
NEW QUESTION # 43
Your security team is noticing that certain privacy-sensitive information such as the URL, HTTP Header and POST bodies are missing from HTTP related detections.
What is likely the cause for this?
- A. The network perimeter firewall blocked the HTTP connection attempts so there was nothing for Falcon to detect
- B. The prevention policy has been configured to redact HTTP detection details
- C. The prevention policy was never configured to generate HTTP detections
- D. The prevention policy was configured to have an aggressive prevention setting, but only a cautious detection setting
Answer: B
NEW QUESTION # 44
Which role allows a user to connect to hosts using Real-Time Response?
- A. Endpoint Manager
- B. Real Time Responder ?Active Responder
- C. Prevention Hashes Manager
- D. Falcon Administrator
Answer: B
Explanation:
The role that allows a user to connect to hosts using Real-Time Response is Real Time Responder ?Active Responder. This role allows users to use the "Connect to Host" feature to gather additional information from the host, as well as execute commands and scripts on the host. The other roles do not have this capability.
NEW QUESTION # 45
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the
20-minute default provisioning window?
- A. Timeout=0
- B. Timeout=30
- C. ProvNoWait=1
- D. ExtendedWindow=1
Answer: C
Explanation:
"ProvNoWait=1
The sensor does not abort installation if it can't connect to the CrowdStrike cloud within 20 minutes (10 minutes, in Falcon sensor version 6.21 and earlier). (By default, if the host can't contact our cloud, it will retry the connection for 20 minutes. After that, the host will automatically uninstall its sensor.)"
"ProvWaitTime=3600000
The sensor waits for 1 hour to connect to the CrowdStrike cloud when installing (the default is 20 minutes)."
NEW QUESTION # 46
Which default user role will allow you to see all analyst session details?
- A. Real Time Response - Administrator
- B. Real Time Response - Read-Only Analyst
- C. Real Time Response - Active Responder
- D. Falcon Administrator
Answer: D
NEW QUESTION # 47
......
CCFA-200b Exam Brain Dumps - Study Notes and Theory: https://actualtorrent.exam4pdf.com/CCFA-200b-dumps-torrent.html

