
CrowdStrike Certified Falcon Administrator CCFA-200 Practice Test Engine: Try These 152 Exam Questions
Guaranteed Success in CrowdStrike Certified Falcon Administrator CCFA-200 Exam Dumps
CrowdStrike CCFA-200 (CrowdStrike Certified Falcon Administrator) Exam is a certification exam designed for IT professionals who have expertise in managing and administering the CrowdStrike Falcon platform. CCFA-200 exam is intended to test the candidate's knowledge and skills in deploying, configuring, and managing the CrowdStrike Falcon platform to ensure the security of an organization's IT environment. CCFA-200 exam validates the candidate's proficiency in performing various tasks such as threat hunting, incident response, and vulnerability management using CrowdStrike Falcon.
The CCFA-200 certification exam is suitable for IT professionals who are responsible for endpoint security in their organization. CCFA-200 exam covers a wide range of topics, including endpoint protection fundamentals, threat intelligence, incident response, and advanced Falcon capabilities. Candidates are expected to have a deep understanding of endpoint security concepts, as well as experience in deploying and managing endpoint protection solutions.
NEW QUESTION # 54
How can a Falcon Administrator configure a pop-up message to be displayed on a host when the Falcon sensor blocks, kills or quarantines an activity?
- A. By enabling "Upload quarantined files" in the General Settings configuration page
- B. By ensuring each user has set the "pop-ups allowed" in their User Profile configuration page
- C. By turning on the "Notify End Users" setting at the top of the Prevention policy details configuration page
- D. By selecting "Enable pop-up messages" from the User configuration page
Answer: C
NEW QUESTION # 55
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
- A. Custom Alert History
- B. Falcon UI Audit Trail
- C. Workflow Execution log
- D. Workflow Audit log
Answer: C
Explanation:
Explanation
The Workflow Execution log in the Workflow Management option allows you to view the status and results of workflow executions triggered by detection events. You can filter the log by workflow name, status, start and end time, and detection ID. You can also view the details of each execution, including the actions performed, the output received, and any errors encountered. This log can help you troubleshoot potential failures or issues with your workflows1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 56
What information does the API Audit Trail Report provide?
- A. A list of specific changes to prevention policy
- B. A list of analyst login activity
- C. A list of actions taken via Falcon OAuth2-based APIs
- D. A list of newly added hosts
Answer: C
Explanation:
Explanation
The information that the API Audit Trail Report provides is a list of actions taken via Falcon OAuth2-based APIs.
The API Audit Trail Report allows you to view and audit the activity and usage of the Falcon APIs by different API clients and users in your organization.
You can use this report to monitor who accessed what data, when, and how via the Falcon APIs2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 57
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
- A. Endpoint ID (EID)
- B. Agent ID (AID)
- C. Computer ID (CID)
- D. Security ID (SID)
Answer: B
NEW QUESTION # 58
Which of the following is TRUE regarding disabling detections for a host?
- A. The detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled
- B. After disabling detections, the host will operate in Reduced Functionality Mode (RFM) until detections are enabled
- C. After disabling detections, the data for all existing detections prior to disabling detections is removed from the Event Search
- D. The DetectionSummaryEvent continues being sent to the Streaming API for that host
Answer: A
Explanation:
Explanation
The option that is true regarding disabling detections for a host is that the detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled. This option is essentially a repetition of question 127 and its answer. Disabling detections for a host will remove any existing detections for that host from the console and prevent any new detections from appearing in the console until detections are enabled again1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 59
When the Notify End Users policy setting is turned on, which of the following is TRUE?
- A. End users will receive a pop-up allowing them to confirm or refuse a pending quarantine
- B. End users will be immediately notified via a pop-up that their machine is in-network isolation
- C. End-users receive a pop-up notification when a prevention action occurs
- D. End users will not be notified as we would not want to notify a malicious actor of a detection. This setting does not exist
Answer: C
NEW QUESTION # 60
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
- A. Prevention Hashes Ignored
- B. Machine-Learning Prevention Monitoring
- C. Prevention Policy Debug
- D. Prevention Policy Audit Trail
Answer: B
Explanation:
Explanation
Audit logs --> Machine-learning prevention monitoring It shows the count of ML expected detections based on the detection levels for a defined time period and the list of files that would be detected on each detection level.
NEW QUESTION # 61
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?
- A. Remediation Manager
- B. Falcon Analyst - Read Only
- C. Real Time Responder - Active Responder
- D. Real Time Responder - Read Only Analyst
Answer: B
NEW QUESTION # 62
Which is the correct order for manually installing a Falcon Package on a macOS system?
- A. Install the Falcon package, then register the Falcon Sensor via the registration package
- B. Register the Falcon Sensor via command line, then install the Falcon package
- C. Install the Falcon package, then register the Falcon Sensor via command line
- D. Register the Falcon Sensor via the registration package, then install the Falcon package
Answer: B
NEW QUESTION # 63
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
- A. Auto - TEST-QA
- B. Specific sensor version number
- C. Auto - N-1
- D. Sensor version updates off
Answer: B
NEW QUESTION # 64
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
- A. From a command line, run the sc query csagent -version command
- B. Use the Sensor Report to filter to the specific endpoint
- C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details
- D. Use the Investigate > Host Search to filter to the specific endpoint
Answer: A
Explanation:
Explanation
From a command line, running the sc query csagent -version command is not a way to determine the sensor version installed on a specific endpoint. This command will only show the status of the csagent service, not the sensor version. The other options are valid ways to determine the sensor version installed on a specific endpoint using Falcon UI or API. You can use the Sensor Report, the Host Search, or the Host Management features to filter, search, or select the desired endpoint and view the sensor version information12.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike 2: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 65
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?
- A. 90 Days
- B. 75 Days
- C. 60 Days
- D. 45 Days
Answer: A
Explanation:
Explanation
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform. You can restore an inactive host from the Trash page if it becomes active again within 90 days1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 66
To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?
- A. Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block
- B. Using IOC management, import the list of hashes and IP addresses and set the action to No Action
- C. Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead
- D. Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only
Answer: C
Explanation:
Explanation
IOC management only allows "Detect only" and "No Action" among the possible actions. Therefore, it cannot be used to block based on IPs or domains. Custom IOA Rule groups allow to create rule types based on Network Connection (configuring a remote IP address) and domains, and gives the options to "Monitor",
"Detect" and "Kill Process", being the late one the closest to "block".
NEW QUESTION # 67
Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
- A. Engine (Full Visibility)
- B. Script-based Execution Monitoring
- C. Suspicious Scripts and Commands
- D. FileSystem Visibility
Answer: B
Explanation:
Explanation
The prevention policy setting that monitors contents of scripts and shells for execution of malicious content on compatible operating systems is Script-based Execution Monitoring. Script-based Execution Monitoring is a feature that enables the Falcon sensor to monitor and prevent malicious script execution on Windows systems.
The feature uses machine learning and behavioral analysis to detect suspicious scripts or commands executed by various script interpreters, such as PowerShell, WScript, CScript, or Bash. You can enable or disable Script-based Execution Monitoring in the Prevention Policy for Windows hosts1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 68
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?
- A. Real Time Responder - Administrator
- B. Real Time Responder - Script Developer
- C. Real Time Responder - Active Responder
- D. Real Time Responder - Read Only Analyst
Answer: A
Explanation:
Explanation
Real Time Responder - Administrator (RTR Administrator) - Can do everything RTR Active Responder can do, plus create custom scripts, upload files to hosts using the put command, and directly run executables using the run command.
NEW QUESTION # 69
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
- A. From a command line, run the sc query csagent -version command
- B. Use the Sensor Report to filter to the specific endpoint
- C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details
- D. Use the Investigate > Host Search to filter to the specific endpoint
Answer: A
NEW QUESTION # 70
What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?
- A. An IOA exclusion
- B. A Sensor Visibility exclusion
- C. A Machine Learning exclusion
- D. A Custom IOC entry
Answer: D
Explanation:
Explanation
The most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally is to create a Custom IOC entry. A Custom IOC (indicator of compromise) entry allows you to define custom rules for detecting or preventing malicious activity based on file hashes, file paths, IP addresses, or domains. You can use regex (regular expression) syntax to create a Custom IOC entry that matches the folder path that you want to block from being uploaded to the cloud1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 71
What are custom alerts based on?
- A. User defined Splunk queries
- B. Custom workflows
- C. Predefined alert templates
- D. Custom event based triggers
Answer: D
NEW QUESTION # 72
Under which scenario can Sensor Tags be assigned?
- A. While triaging a detection
- B. While updating a sensor in the Falcon console
- C. While installing a sensor
- D. While managing hosts in the Falcon console
Answer: D
NEW QUESTION # 73
On the Host management page which filter could be used to quickly identify all devices categorized as a
"Workstation" by the Falcon Platform?
- A. Platform
- B. Type
- C. Status
- D. Hostname
Answer: B
Explanation:
Explanation
The filter that could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform on the Host Management page is Type. The Type filter allows you to filter hosts by their device type, such as workstation, server, or domain controller. The device type is assigned to each host based on their Active Directory domain structure. You can use the Type filter to quickly identify all hosts that have the workstation type assigned in their domain2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 74
......
CrowdStrike CCFA-200 exam is a certification that validates the skills and knowledge of administrators who manage and maintain the CrowdStrike Falcon platform. CCFA-200 exam covers a wide range of topics, including threat intelligence, endpoint detection and response, incident response, and malware analysis. By passing CCFA-200 exam, administrators can demonstrate their expertise in using the Falcon platform and their ability to protect their organization against cyber threats.
Test Engine to Practice CCFA-200 Test Questions: https://www.actualtorrent.com/CCFA-200-questions-answers.html
CrowdStrike CCFA-200 Daily Practice Exam New 2023 Updated 152 Questions: https://drive.google.com/open?id=1Rk1WS_e9bFQRMuJvQ_1kSiWbY3tBqPXq