View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 41
What is the default quarantine behavior for executable files detected as malicious by Machine Learning in Falcon Prevent?
- Files are automatically renamed and moved to a public network folder
- Files are quarantined immediately if the Machine Learning threshold rule is set to Quarantine
- Files are left in place but stripped of administrative permissions
- Files are encrypted with a private key and emailed to the user
Correct Answer: 2
Explanation:
When Machine Learning detection thresholds trigger a block action and Quarantine enforcement is enabled in the Prevention Policy, the Falcon sensor automatically isolates and secures the malicious executable file from the file system. The file is safely moved into an encrypted local quarantine repository managed by the sensor, preventing execution, lateral movement, or further system damage while preserving the binary for administrator review and forensic examination.
Question 42
An administrator wants to ensure that a newly created Sensor Update Policy applies to a specific subset of servers. How is this achieved in the Falcon console?
- By manually entering the IP addresses into the Cloud Update Console
- By assigning the Sensor Update Policy directly to the targeted Host Group
- By running a local CLI update command on each target machine
- By modifying the global system environment variables on the endpoints
Correct Answer: 2
Explanation:
In the CrowdStrike Falcon console, policy management relies on Host Groups to target configurations cleanly. To apply a custom Sensor Update Policy to a designated group of servers, the administrator assigns the policy to the corresponding Host Group. Host Group scoping allows security teams to control update velocity, test initial builds on staging environments, and ensure production servers receive updates according to defined maintenance schedules.
Question 43
Which feature in CrowdStrike Falcon allows security teams to create custom detection rules based on unique file behavior and command-line parameters?
- Custom IOAs (Indicators of Attack)
- Custom Firewalls
- Scheduled Scans
- Device Control Policies
Correct Answer: 1
Explanation:
Custom Indicators of Attack (IOAs) empower security teams to write tailored behavioral rules using regular expressions, parent-child process trees, and command-line parameters. Unlike static hash matches, Custom IOAs evaluate dynamic execution patterns on the endpoint. This allows organizations to flag or block internal policy violations, suspicious administrative scripts, or organization-specific threat behaviors in real time as they occur across endpoints.
Question 44
What happens to telemetry collected by a Falcon sensor when the endpoint loses internet connectivity for an extended period?
- Telemetry is dropped immediately to conserve local memory
- Telemetry is stored in a local disk cache and uploaded once connectivity is restored
- Telemetry is sent to local Windows Event Logs instead of the cloud
- The sensor uninstalls itself automatically to prevent data corruption
Correct Answer: 2
Explanation:
The Falcon sensor is engineered to operate seamlessly during network disruptions. When an endpoint loses connection to the CrowdStrike cloud, the sensor caches telemetry locally in a secure, ring-buffered storage area on disk. Once internet connectivity is re-established, the sensor securely uploads the buffered events to the cloud for processing, ensuring that security teams retain historical visibility without losing critical operational event logs.
Question 45
Which role within the Falcon console provides read-only access to detection details and host inventories without allowing policy modifications?
- Falcon Administrator
- Falcon Analyst
- Security Investigator (Read Only)
- System Administrator
Correct Answer: 3
Explanation:
The Security Investigator (Read Only) role is tailored for compliance officers, auditors, or tier-1 triage analysts who require visibility into system detections, threat graph details, and endpoint inventories without administrative permissions. This role restricts users from modifying prevention policies, managing sensor update rules, initiating containment actions, or altering system-wide console configurations.
Question 46
How can an administrator verify that a Windows endpoint has successfully registered with the CrowdStrike cloud after sensor installation?
- Check the local Task Manager for CSFalconService.exe and confirm host presence in Host Management
- Run a full system antivirus scan using cmd.exe
- Ping falcon.crowdstrike.com from the command prompt
- Verify that the computer name appears in the local active directory root folder
Correct Answer: 1
Explanation:
To verify successful installation and registration on a Windows host, administrators check that the core sensor service (CSFalconService.exe) is actively running in system services or Task Manager. Additionally, they confirm that the machine appears on the Host Management page in the Falcon console with an active status and an assigned Agent ID (AID), ensuring continuous telemetry streaming.
Question 47
What is the primary function of CrowdStrike Falcon Device Control?
- Managing network interface card speeds
- Restricting and auditing the use of USB storage devices and removable media
- Updating operating system graphics drivers
- Controlling remote desktop protocol connections
Correct Answer: 2
Explanation:
CrowdStrike Falcon Device Control provides visibility and policy enforcement over USB mass storage devices and removable media connected to enterprise endpoints. Administrators can configure policies to block unauthorized storage devices, set read-only permissions for specific USB classes, or log file transfers, mitigating the risks of physical data exfiltration and malware insertion via external storage devices.
Question 48
Which built-in module provides network-level visibility and central management for host firewall rules?
- Falcon Firewall Management
- Falcon Discover
- Falcon Insight
- Falcon Horizon
Correct Answer: 1
Explanation:
Falcon Firewall Management simplifies host-based firewall policy creation, management, and enforcement directly from the cloud console. It manages native Windows and macOS firewall controls through a single interface, allowing security operations teams to enforce network segmentation, block unauthorized inbound or outbound ports, and streamline compliance auditing across heterogeneous enterprise endpoints.
Question 49
What is the purpose of configuring Sensor Maintenance Tokens in the Falcon console?
- To grant temporary access to external security auditors
- To allow authorized administrators to uninstall or modify the sensor on protected hosts
- To generate API keys for automated SOAR scripts
- To extend the license expiration date of the Falcon platform
Correct Answer: 2
Explanation:
Sensor Maintenance Tokens work alongside Tampering Protection to prevent unauthorized sensor uninstallation or tampering. When Sensor Tampering Protection is enabled, local users—even those with local administrator privileges—cannot uninstall or repair the sensor without providing a unique, time-sensitive maintenance token generated directly from the Falcon console by an authorized administrator.
Question 50
In Falcon Insight, what does the Process Timeline display during incident triage?
- Historical CPU usage graphs for the host machine
- Chronological sequence of file creation, network connections, and process executions
- Scheduled operating system update tasks
- Active VPN user sessions over the last 30 days
Correct Answer: 2
Explanation:
The Process Timeline in Falcon Insight offers security analysts a detailed chronological breakdown of execution events surrounding an alert. It visually details parent and child process creation, command-line arguments, network connections, file modifications, and registry changes, enabling incident responders to quickly construct an accurate narrative of how an attack originated and progressed.
Question 51
Which type of exclusion is best suited for suppressing false positives generated by behavioral Indicators of Attack (IOAs)?
- Machine Learning Exclusions
- IOA Exclusions
- Hash Exclusions
- USB Device Exclusions
Correct Answer: 2
Explanation:
IOA Exclusions are designed to suppress alerts generated by specific behavioral rules and Indicators of Attack without disabling underlying platform protections. By defining targeted parameters like process paths, command-line wildcards, or parent processes, administrators can allow legitimate administrative scripts or internal software tools to execute without triggering false positive alerts in the console.
Question 52
When deploying the Falcon sensor via command line on Windows, which parameter is mandatory to pair the sensor with your organization’s tenant?
- CID=<Customer_ID>
- LICENSE=<License_Key>
- GROUP=<Host_Group>
- SERVER=<Cloud_URL>
Correct Answer: 1
Explanation:
The CID=<Customer_ID> parameter is mandatory when installing the Falcon sensor via command-line interface (CLI) or deployment tools on Windows. The Customer ID (CID) authenticates the agent with your specific CrowdStrike cloud instance and links the newly registered endpoint to your organization’s tenant environment. Without the CID, the sensor cannot successfully register or stream telemetry.
Question 53
What information does Falcon Discover collect regarding software applications?
- Software source code and developer comments
- Installed application names, versions, vendor details, and host counts
- Real-time application frame rates and GPU usage
- Cloud backup status of application data files
Correct Answer: 2
Explanation:
Falcon Discover provides IT and security teams with inventory visibility by discovering installed applications across enterprise endpoints. It indexes software inventory details including application names, version numbers, publisher vendor details, and total installation counts across the environment, helping organizations identify legacy software, unauthorized applications, and unpatched versions.
Question 54
What is the primary benefit of the cloud-native Threat Graph in the CrowdStrike platform?
- Automated local hard drive defragmentation
- Real-time event correlation and cross-customer threat intelligence sharing at scale
- Encrypted cloud storage for personal user documents
- Automatic generation of local system backup images
Correct Answer: 2
Explanation:
CrowdStrike’s Threat Graph processes trillions of security events daily from global endpoints. Its cloud-native design enables real-time data correlation, tracking process relationships, and instantaneous threat intelligence distribution. When a novel adversary technique or malicious indicator is detected in one environment, Threat Graph immediately updates protections for all CrowdStrike customers worldwide.
Question 55
Which status indicates that a host’s network traffic has been completely isolated from the local network and internet, except for communication with CrowdStrike?
- Quarantined
- Contained
- Offline
- Disabled
Correct Answer: 2
Explanation:
A host status of “Contained” signifies that Network Containment has been applied via the Falcon console. Network Containment isolates the machine at the driver level, severing all internal and external network communication to prevent lateral movement or data exfiltration, while maintaining an active channel with the CrowdStrike cloud so analysts can investigate and remediate remotely.
Question 56
What function does the CrowdStrike Falcon Sensor Update Policy serve?
- It schedules Windows OS update downloads
- It controls sensor software versions and manages phased software update rollouts
- It updates local antivirus signature databases every hour
- It manages firewall rule updates across cloud infrastructure
Correct Answer: 2
Explanation:
Sensor Update Policies give administrators central control over sensor version management. Teams can pin specific host groups to fixed sensor builds, test new releases in staging environments before global deployment, or enable automatic updates to ensure systems run recent sensor versions without causing unexpected operational downtime.
Question 57
What capability does Real Time Response (RTR) provide to security operations teams?
- Automated mass emailing to end-users during incidents
- Interactive command-line access to remote endpoints for triage and remediation
- Automatic system BIOS updates across remote hosts
- Cloud proxy traffic rerouting for remote workers
Correct Answer: 2
Explanation:
Real Time Response (RTR) provides authorized security analysts with an interactive, secure command-line connection to remote endpoints. Through RTR, analysts can inspect active processes, retrieve forensic artifacts, terminate malicious tasks, remove persistence mechanisms, and execute remediation scripts directly on remote devices, significantly accelerating incident response times.
Question 58
What is the recommended approach for testing new Falcon sensor releases before enterprise-wide deployment?
- Deploy the release immediately to all production servers on weekends
- Assign a small representative host group to a Sensor Update Policy configured with the new release
- Manually copy installation files to user desktop folders
- Disable prevention policies across all test systems during installation
Correct Answer: 2
Explanation:
Best practices for sensor lifecycle management dictate testing new releases on a representative host group (such as non-critical dev/test systems or pilot user groups) using a targeted Sensor Update Policy. This phased rollout strategy allows teams to validate application compatibility and operational stability before promoting the update to production environments.
Question 59
In Falcon Incident Management, what does an Incident represent?
- A single failed user login attempt
- A correlated collection of related detections and behaviors forming an adversary campaign
- An expired system SSL certificate log
- A daily summary of system uptime performance
Correct Answer: 2
Explanation:
An Incident in the Falcon console is a high-fidelity alert grouping that correlates multiple individual detections, behavioral indicators, and host events occurring across the enterprise into a unified narrative. By aggregating related events into a single incident, CrowdStrike helps analysts assess adversary campaigns, scope tactics, and prioritize response efforts efficiently.
Question 60
Which feature in CrowdStrike Falcon allows users to automate containment, notification, and ticket creation workflows?
- Falcon Fusion
- Falcon Spotlight
- Falcon FileVantage
- Falcon Discover
Correct Answer: 1
Explanation:
Falcon Fusion is CrowdStrike’s integrated SOAR (Security Orchestration, Automation, and Response) engine. It allows administrators to build automated workflows using customizable triggers, conditions, and actions. Teams can automate routine tasks such as sending notification alerts via Slack/Teams, isolating compromised hosts, creating ticketing system records, or executing remediation scripts based on real-time detections.