
[Apr-2026 Newly Released] CCFA-200b Dumps for CrowdStrike Certified Falcon Administrator Certified
Updated Verified CCFA-200b dumps Q&As - 100% Pass
CrowdStrike CCFA-200b Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 24
Which of the following can a Falcon Administrator edit in an existing user's profile?
- A. Working groups
- B. Email address
- C. Phone number
- D. First or Last name
Answer: D
Explanation:
Roles are never called 'working groups' in the documentation. The only other option that can be edited on a existing user is first and last name.
NEW QUESTION # 25
When creating new IOCs in IOC management, which of the following fields must be configured?
- A. Filename, Severity and Expiry Date
- B. Hash, Platform and Action
- C. Hash, Description, Filename
- D. Hash, Action and Expiry Date
Answer: B
Explanation:
When creating new IOCs in IOC management, the administrator must configure the Hash, Platform and Action fields. The Hash field is the value of the IOC, such as MD5, SHA1 or SHA256. The Platform field is the operating system that the IOC applies to, such as Windows, Linux or Mac. The Action field is the action that Falcon will take when detecting the IOC, such as Detect, Block or Allow. The other fields are either optional or not available.
NEW QUESTION # 26
What is the function of a single asterisk (*) in an ML exclusion pattern?
- A. The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path
- B. The single asterisk is only used to start an expression, and it represents the drive letter
- C. The single asterisk is the insertion point for the variable list that follows the path
- D. The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path
Answer: D
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/machine-learning The asterisk is a wildcard character that can be used in exclusion patterns to match any number of characters. However, it does not match separator characters, such as \ or /, which are used to separate portions of a file path. For example, the pattern C:\Windows\*\*.exe will match any executable file in any subfolder of the Windows folder, but not in the Windows folder itself.
NEW QUESTION # 27
Which role is required to manage groups and policies in Falcon?
- A. Prevention Hashes Manager
- B. Falcon Host Security Lead
- C. Falcon Host Analyst
- D. Falcon Host Administrator
Answer: D
Explanation:
The Falcon Host Administrator role is required to manage groups and policies in Falcon. This role allows users to create, edit and delete groups and policies, as well as assign them to hosts. The other roles do not have this capability. Reference: [CrowdStrike Falcon User Guide], page 17.
NEW QUESTION # 28
You want to create a detection-only policy. How do you set this up in your policy's settings?
- A. You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.
- B. Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.
- C. Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.
- D. Select the "Detect-Only" template. Disable hash blocking and exclusions.
Answer: C
Explanation:
The administrator can create a detection-only policy by setting the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled in the policy's settings. This will allow Falcon to detect but not prevent threats on the hosts using this policy. Do not activate any of the other blocking or malware prevention options, as they will enable prevention actions. The other options are either incorrect or not related to creating a detection- only policy.
NEW QUESTION # 29
Which prevention policy setting monitors contents of scripts and shells for execution of malicious content?
- A. Engine (Full Visibility)
- B. Suspicious Scripts and Commands
- C. FileSystem Visibility
- D. Script-based Execution Monitoring
Answer: D
NEW QUESTION # 30
During a simulated training exercise with your security team, an analyst used Falcon to network contain a host. It was then discovered that containing this specific host interrupted some key business processes and resulted in lost revenue.
As the Falcon Administrator, what can be done to prevent this interruption in the future?
- A. Add this Falcon host to your deny list so that it is never able to be network contained again
- B. Collaborate with the firewall engineers so that in the future, network containment would only deny external IP addresses and no internal IP addresses
- C. Configure your containment policy to allow the IP addresses for those key business processes so that your hosts will be allowed to communicate with them, even if those hosts are contained
- D. Educate the analyst so they can understand and memorize which hosts are safe to network contain, and which would cause harm if contained
Answer: C
NEW QUESTION # 31
How does the Unique Hosts Connecting to Countries Map help an administrator?
- A. It highlights countries with known malware
- B. It identifies connections containing threats
- C. It helps visualize global network communication
- D. It displays intrusions from foreign countries
Answer: C
Explanation:
The Unique Hosts Connecting to Countries Map helps an administrator to visualize global network communication. The map shows the number of unique hosts in your environment that have established network connections to different countries in the past 24 hours. You can use this map to identify unusual or suspicious network activity, such as connections to high-risk countries or regions, or connections from hosts that are not expected to communicate with external entities.
NEW QUESTION # 32
Assume the Falcon Sensor was installed on a Virtual Machine template using the installation parameter NO_START=1. Afterward, the Virtual Machine template is rebooted. What is the effect on the Falcon Sensor after reboot?
- A. The Falcon Sensor would not automatically start on reboot. It would have to be manually started
- B. The Falcon Sensor would start at reboot and generate an Agent ID.
- C. The Falcon Sensor would disable BIOS checks at startup
- D. The Falcon Sensor would start, but only send a heartbeat to the Falcon console
Answer: A
NEW QUESTION # 33
Why is the ability to disable detections helpful?
- A. It gives users the ability to allowlist a false positive detection
- B. It gives users the ability to uninstall the sensor from a host
- C. It gives users the ability to set up hosts to test detections and later remove them from the console
- D. It gives users the ability to remove all data from hosts that have been uninstalled
Answer: C
NEW QUESTION # 34
Custom IOA rules are defined using which syntax?
- A. Regex
- B. Yara
- C. Glob
- D. PowerShell
Answer: A
NEW QUESTION # 35
Your organization has determined that your cybersecurity architect needs to be notified via email whenever Falcon generates detections of a medium severity or higher. Additionally, the architect should be notified about any incidents with a CrowdScore of 1.0 or higher.
What can the Falcon Administrator do to ensure the architect is properly alerted?
- A. Create a custom Fusion SOAR workflow to send an email every time a new detection or incident is created
- B. Create a new Falcon user for the architect and assign the Detections and Exceptions Manager role so they are automatically notified for the new detections and incidents
- C. Add the architect's email address to the manage list for detection and incident emails from the General settings menu
- D. Create a new Falcon user for the architect then create and assign a custom Falcon user role so they are automatically notified for the new detections and emails
Answer: A
NEW QUESTION # 36
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?
- A. TCP port 443 (HTTPS)
- B. TCP port 22 (SSH)
- C. TCP UDP port 53 (DNS)
- D. TCP port 80 (HTTP)
Answer: A
Explanation:
The sensor uses TCP port 443 (HTTPS) to communicate with the CrowdStrike Cloud. This port and protocol are used to securely send and receive data between the sensor and the cloud, such as detections, policies, updates, commands, etc. The other options are either incorrect or not used by the sensor.
NEW QUESTION # 37
What is the purpose of the "Auto - Latest" setting in a sensor update policy?
- A. This setting will cause all assigned hosts to be updated to the most current version as soon as it becomes available
- B. This setting automatically assigns new hosts that come online to this policy
- C. This setting automatically assigns the latest Indicator of Attack (IOA) profiles and Next-Gen Antivirus (NGAV) machine learning to the selected endpoints ensuring the highest level of security
- D. This setting overrides any user confirmation/interaction and applies the selected policy
Answer: A
NEW QUESTION # 38
What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
- A. A misconfiguration in your prevention policy for the host
- B. Microsoft updates altering the kernel
- C. The host lost internet connectivity
- D. A Sensor Update Policy was misconfigured
Answer: C
Explanation:
The likely reason your Windows host would be in Reduced Functionality Mode (RFM) is that the host lost internet connectivity. RFM is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. When a Windows sensor is in RFM, it will only provide basic prevention capabilities, such as blocking known malware hashes and preventing script execution from the %TEMP% directory. The sensor will not send any telemetry or detection events to the Falcon platform, and will not receive any policy or update changes from the Falcon cloud1. Losing internet connectivity is a common cause of RFM, as it prevents the sensor from communicating with the Falcon cloud. A misconfiguration in your prevention policy or sensor update policy will not cause RFM, as these policies are applied by the Falcon cloud and do not affect the sensor's license, network, or certificate status. Microsoft updates altering the kernel may cause compatibility issues with the sensor, but not RFM.
NEW QUESTION # 39
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
- A. Sensor Visibility Exclusion
- B. Machine Learning Exclusions
- C. IOC Exclusions
- D. IOA Exclusions
Answer: D
Explanation:
The option that should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax is IOA Exclusions. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. However, using IOA exclusions may reduce the visibility and protection of the Falcon sensor, as it may allow malicious activity to bypass the sensor's detection and prevention capabilities. Therefore, you should use IOA exclusions with extreme caution and only when necessary.
NEW QUESTION # 40
You are creating a new host group that needs to contain all of the servers in your environment regardless of the installed operating system.
Which filter should be applied to the group's assignment rule to accomplish this task?
- A. Type - Server
- B. Build - Server
- C. Model - Server
- D. Manufacturer-All
Answer: A
NEW QUESTION # 41
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
- A. SSL inspection should be configured to occur on all Falcon traffic
- B. Common sources of interference with certificate pinning include protocol race conditions and resource contention
- C. Some network configurations, such as deep packet inspection, interfere with certificate validation
- D. HTTPS interception should be enabled to proceed with certificate validation
Answer: C
Explanation:
The statement that some network configurations, such as deep packet inspection, interfere with certificate validation is true concerning Falcon sensor certificate validation. The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks, which means that it verifies that the server certificate presented by the Falcon cloud matches a hard-coded certificate embedded in the sensor. Some network configurations, such as deep packet inspection, SSL inspection, or HTTPS interception, may attempt to modify or replace the server certificate, which will cause the sensor to reject the connection and generate an error.
NEW QUESTION # 42
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
- A. Falcon Ul Audit Trail
- B. Workflow Execution log
- C. Custom Alert History
- D. Workflow Audit log
Answer: B
Explanation:
The place where you can find the history of the successes and failures for any Falcon Fusion workflows is the Workflow Execution log. The Workflow Execution log in the Workflow Management option allows you to view the status and results of workflow executions triggered by detection events. You can filter the log by workflow name, status, start and end time, and detection ID. You can also view the details of each execution, including the actions performed, the output received, and any errors encountered. This log can help you troubleshoot potential failures or issues with your workflows.
NEW QUESTION # 43
Which role will allow someone to manage quarantine files?
- A. Detections Exceptions Manager
- B. Falcon Security Lead
- C. Endpoint Manager
- D. Falcon Analyst ?Read Only
Answer: B
Explanation:
The role that will allow someone to manage quarantine files is Falcon Security Lead. This role allows users to view and manage quarantined files, as well as release them from quarantine or download them for further analysis. The other roles do not have this capability.
NEW QUESTION # 44
Which of the following would give you information about inactive sensors within the Falcon console?
- A. Sensor Update Policies
- B. Sensor Downloads
- C. Sensor Health
- D. Sensor Coverage Lookup
Answer: C
NEW QUESTION # 45
How do you assign a Prevention policy to one or more hosts?
- A. Create a new policy and assign it directly to those hosts on the Prevention policy page
- B. Modify the users roles on the User Management page
- C. Create a new policy and assign it directly to those hosts on the Host Management page
- D. Ensure the hosts are in a group and assign that group to a custom Prevention policy
Answer: D
Explanation:
The administrator can assign a Prevention policy to one or more hosts by ensuring the hosts are in a group and assigning that group to a custom Prevention policy. This allows users to apply different prevention settings and options to different groups of hosts based on their needs and preferences. The other options are either incorrect or not applicable to assigning a Prevention policy.
NEW QUESTION # 46
......
Latest CCFA-200b Exam Dumps CrowdStrike Exam from Training: https://www.crampdf.com/CCFA-200b-exam-prep-dumps.html
New 2026 Latest Questions CCFA-200b Dumps - Use Updated CrowdStrike Exam: https://drive.google.com/open?id=1Bpta4A08ypuLQnCKKmMQDzVZ9l9-9D8q