
Download Free CrowdStrike CCFA-200 Exam Questions & Answer
Online VALID CCFA-200 Exam Dumps File Instantly
CrowdStrike CCFA-200 Certification Exam is designed for individuals who wish to demonstrate their expertise in managing and administering the CrowdStrike Falcon platform. CrowdStrike Certified Falcon Administrator certification exam is designed to test the candidate's knowledge and skills in various areas of Falcon's administration, including endpoint protection, threat intelligence, incident response, and advanced hunting. The CCFA-200 certification exam is a vendor-specific certification that is recognized by CrowdStrike, a leading provider of cloud-based endpoint protection solutions.
CrowdStrike CCFA-200 certification exam consists of 60 multiple-choice questions and has a time limit of 90 minutes. CCFA-200 exam covers a variety of topics, including the installation and configuration of CrowdStrike Falcon agents, the management of policies and rules, and the use of the Falcon console for incident response and threat hunting.
CrowdStrike CCFA-200 certification exam is an industry-leading certification that is designed to validate the skills and knowledge of individuals who are responsible for managing and administering the CrowdStrike Falcon platform. CCFA-200 exam is intended for security professionals who are looking to build their careers in the cybersecurity field, and it is a highly respected certification that is recognized by industry leaders worldwide.
NEW QUESTION # 26
Which of the following is TRUE of the Logon Activities Report?
- A. Shows a graphical view of user logon activity and the hosts the user connected to
- B. It gives a detailed list of all logon activity for users
- C. The report can be filtered by computer name
- D. It only gives a summary of the last logon activity for users
Answer: B
NEW QUESTION # 27
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?
- A. File exclusions are not aligned to groups or hosts
- B. There is a limit of three groups of hosts applied to any exclusion
- C. There is no limit and exclusions can be applied to any or all groups
- D. Each exclusion can be aligned to only one group of hosts
Answer: C
Explanation:
Explanation
An exclusion is a rule that tells the Falcon platform to ignore certain files, folders, processes, or registry keys when performing prevention or detection actions. An administrator can create an exclusion and apply it to one or more groups of hosts, or to all hosts in the organization. For example, an administrator can create an exclusion for a legitimate application that is causing false positives and apply it to the group of hosts that are running that application.
NEW QUESTION # 28
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
- A. Sensor Visibility Exclusion
- B. IOC Exclusions
- C. IOA Exclusions
- D. Machine Learning Exclusions
Answer: C
Explanation:
Explanation
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 29
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
- A. *nix
- B. Both Windows and *nix
- C. Only Mac
- D. Windows
Answer: B
NEW QUESTION # 30
Which of the following is NOT an available filter on the Hosts Management page?
- A. Hostname
- B. OS Version
- C. Group
- D. Username
Answer: D
NEW QUESTION # 31
What are custom alerts based on?
- A. Predefined alert templates
- B. Custom event based triggers
- C. User defined Splunk queries
- D. Custom workflows
Answer: B
NEW QUESTION # 32
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
- A. Workflow Execution log
- B. Custom Alert History
- C. Workflow Audit log
- D. Falcon UI Audit Trail
Answer: A
NEW QUESTION # 33
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
- A. Under Host setup and management, choose the Host Management page. Set the group filter to "Inactive Sensors"
- B. Under Host setup and management > Managed endpoints > Inactive Sensors. Change the time range to
30 days - C. Under Dashboards and reports, choose the Sensor Report. Set the "Last Seen" dropdown to 30 days and reference the Inactive Sensors widget
- D. Under Host setup and management, choose the Disabled Sensors Report. Change the time range to 30 days
Answer: B
Explanation:
Explanation
The administrator can find a list of hosts that have not communicated with the CrowdStrike Cloud in the last
30 days by going to Host setup and management > Managed endpoints > Inactive Sensors. Then, change the time range to 30 days. This will show the host name, last seen date, sensor version and group name for each inactive host. The other options are either incorrect or not available. Reference: [CrowdStrike Falcon User Guide], page 31.
NEW QUESTION # 34
What must an admin do to reset a user's password?
- A. From User Management, select "Update Account" and manually create a new password for the affected user account
- B. From User Management, the administrator must rebuild the account as the certificate for user specific private/public key generation is no longer valid
- C. From User Management, open the account details for the affected user and select "Generate New Password"
- D. From User Management, select "Reset Password" from the three dot menu for the affected user account
Answer: D
NEW QUESTION # 35
Which role allows a user to connect to hosts using Real-Time Response?
- A. Endpoint Manager
- B. Prevention Hashes Manager
- C. Real Time Responder - Active Responder
- D. Falcon Administrator
Answer: C
NEW QUESTION # 36
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
- A. Grant the Falcon Package Full Disk Access, install the Falcon package, use falconctl to license the sensor
- B. Install the Falcon package passing it the installation token in the command line
- C. Grant the Falcon Package Full Disk Access, install the Falcon package, load the Falcon Sensor with the command 'falconctl stats'
- D. Install the Falcon package, use falconctl to license the sensor, approve the system extension, grant the sensor Full Disk Access
Answer: D
Explanation:
Explanation
The option that best describes the general process for installation of the Falcon Sensor on MacOS is to install the Falcon package, use falconctl to license the sensor, approve the system extension, grant the sensor Full Disk Access. The Falcon package contains the sensor binary and the kernel extension, which can be installed by double-clicking on it or using a command-line tool such as installer. The falconctl tool is a command-line utility that allows you to configure and manage the sensor on MacOS systems. You can use falconctl to license the sensor by providing your Customer ID (CID) and optionally your Sensor Group ID (SGID). After licensing the sensor, you need to approve the system extension in the Security & Privacy settings of your system preferences, which will require a restart. Finally, you need to grant the sensor Full Disk Access in the Privacy settings of your system preferences, which will allow the sensor to monitor and protect your files and folders1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 37
What information is provided in Logan Activities under Visibility Reports?
- A. A list of last endpoints that a user logged in to
- B. A list of all logons for all users
- C. A list of unique users who are remotely logged on to devices based on the country
- D. A list of users who are remotely logged on to devices based on local IP and local port
Answer: A
Explanation:
Explanation
The Logon Activities report under Visibility Reports provides a list of last endpoints that a user logged in to.
This report shows the user name, domain name, logon type, logon time and endpoint name for each logon event. The other options are either incorrect or not related to the report. Reference: [CrowdStrike Falcon User Guide], page 50.
NEW QUESTION # 38
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
- A. Firewall Rule Group
- B. Machine Learning Exclusions
- C. Containment Policy
- D. USB Device Policy
Answer: B
Explanation:
Explanation
Continment Policy, is a allowlist of IPs and CIDR networks allowed in the moment of a host containtment.
The Machine Learning Exclusions are the way to avoid the detections done it by Machine Learning based on files, so it is possible to exclude the detections for the requested folder with a GLOB expression.
NEW QUESTION # 39
Which of the following is a valid step when troubleshooting sensor installation failure?
- A. Delete any available application crash log files
- B. Confirm all required services are running on the system
- C. Disable SSL and TLS on the host
- D. Enable the Windows firewall
Answer: B
NEW QUESTION # 40
What statement is TRUE about managing a user's role?
- A. You must be a Falcon Administrator
- B. You must be a Falcon Security Lead
- C. The Administrator cannot re-use the account email for a new account
- D. You must have Falcon MFA enabled first
Answer: A
Explanation:
Explanation
The statement that is true about managing a user's role is that you must be a Falcon Administrator. A Falcon Administrator is a role that has full access and control over all features and functions in Falcon, including user management. A Falcon Administrator can create, modify, delete, and assign roles to other users in Falcon. A Falcon Administrator can also re-use the account email for a new account, enable Falcon MFA (multi-factor authentication), and assign other roles such as Falcon Security Lead or Falcon Investigator2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 41
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
- A. Operating System Groups
- B. Enterprise Groups
- C. Custom IOC Groups
- D. Custom IOA Rule Groups
Answer: A
NEW QUESTION # 42
How do you disable all detections for a host?
- A. Create an exclusion rule and apply it to the machine or group of machines
- B. In Host Management, select the host and then choose the option to Disable Detections
- C. Contact support and provide them with the Agent ID (AID) for the machine and they will put it on the Disabled Hosts list in your Customer ID (CID)
- D. You cannot disable all detections on individual hosts as it would put them at risk
Answer: B
Explanation:
Explanation
The administrator can disable all detections for a host by selecting the host and then choosing the option to Disable Detections in the Host Management page. This will prevent the host from sending any detection events to the Falcon Cloud. The other options are either incorrect or not available. Reference: [CrowdStrike Falcon User Guide], page 32.
NEW QUESTION # 43
Where can you modify settings to permit certain traffic during a containment period?
- A. Containment Policy
- B. Host Settings
- C. Firewall Settings
- D. Prevention Policy
Answer: A
NEW QUESTION # 44
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?
- A. 90 Days
- B. 45 Days
- C. 60 Days
- D. 75 Days
Answer: A
Explanation:
Explanation
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after 90 days. An inactive host is a host that has not communicated with the Falcon platform for more than seven days. An inactive host will be moved from the Host Management page to the Trash page after seven days of inactivity. An inactive host will remain in the Trash page for 90 days before being permanently deleted from the Falcon platform. You can restore an inactive host from the Trash page if it becomes active again within 90 days1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 45
When would the No Action option be assigned to a hash in IOC Management?
- A. Add the indicator to your allowlist and do not detect it
- B. Add the indicator to your blocklist and show it as a detection
- C. There is no such option as No Action available in the Falcon console
- D. When you want to save the indicator for later action, but do not want to block or allow it at this time
Answer: D
NEW QUESTION # 46
......
CCFA-200 Exam Dumps For Certification Exam Preparation: https://www.itexamsimulator.com/CCFA-200-brain-dumps.html
100% Pass Guaranteed Download CrowdStrike Certified Falcon Administrator Exam PDF Q&A: https://drive.google.com/open?id=1wT2bADkYdYfc1hSzacPQrHmsnGv84x2X

