View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 101
What is the function of the Falcon Discover IP Network range configuration?
- To block unauthorized IP addresses from reaching local servers
- To define network subnets for identifying unmanaged assets and rogue systems
- To configure dynamic host configuration protocol (DHCP) leases
- To establish VPN tunnel endpoints for remote workers
Correct Answer: 2
Explanation:
The IP network range configuration within Falcon Discover allows security and IT administrators to define specific corporate subnets and network boundaries. By specifying these authorized ranges, the Falcon platform can effectively analyze telemetry and identify unmanaged assets, shadow IT, or unknown devices operating within those segments. This visibility helps organizations ensure complete agent coverage, track network exposure, and maintain a comprehensive asset inventory across physical and virtual environments without requiring intrusive network scanners.
Question 102
How can an administrator verify the version of the Falcon sensor installed on a specific remote endpoint?
- By checking the local Windows desktop wallpaper settings
- By reviewing the host details in the Host Management dashboard or via Real Time Response
- By running a hardware diagnostic check in the BIOS
- By reading the physical router configuration file
Correct Answer: 2
Explanation:
Administrators can easily verify the active Falcon sensor version deployed on any endpoint by navigating to the Host Management dashboard within the Falcon console, where detailed system attributes are listed. Alternatively, administrators with Real Time Response (RTR) permissions can connect to the target endpoint and execute specific query commands to retrieve precise binary version data. This visibility is essential when planning staged software upgrades, verifying update policy enforcement, or troubleshooting compatibility issues across enterprise operating systems.
Question 103
What does a “Pending” status in the Host Management console usually indicate for a newly installed sensor?
- The endpoint has been permanently isolated from the network via Containment
- The sensor has crashed and requires a complete hardware replacement
- The sensor has been installed but has not yet fully checked in or established communication with the CrowdStrike cloud
- The sensor license has expired and all protections are disabled
Correct Answer: 3
Explanation:
A “Pending” status in the Host Management view typically appears immediately after a fresh sensor installation when the agent has been deployed to the operating system but has not yet completed its initial handshake or registration check-in with the CrowdStrike cloud infrastructure. This temporary state usually resolves itself automatically once network connectivity is established, configuration parameters are validated, and telemetry streaming begins successfully, confirming active agent registration.
Question 104
Which Falcon module is primarily used to track user and entity behavior analytics (UEBA) and identity-based threats?
- Falcon Prevent
- Falcon Identity Protection
- Falcon Spotlight
- Falcon Horizon
Correct Answer: 2
Explanation:
Falcon Identity Protection focuses specifically on defending enterprise identity infrastructure by monitoring active directory activities, credential usage, and authentication requests in real time. It detects compromised credentials, lateral movement via stolen tokens, and malicious authentication patterns across hybrid environments. By integrating identity intelligence with endpoint telemetry, security teams can proactively stop identity-based attacks, enforce risk-based conditional access, and secure user accounts before attackers gain elevated administrative privileges.
Question 105
What action should an administrator take if they want to prevent a specific file hash from triggering alerts globally across all host groups?
- Delete the local Windows operating system registry files
- Add a global Hash Exclusion within the applicable Prevention Policy
- Enable network containment on all company workstations
- Format the primary storage drive of the affected server
Correct Answer: 2
Explanation:
When a legitimate internal file or trusted administrative binary is incorrectly flagged across the enterprise, administrators can resolve the issue by configuring a global Hash Exclusion within the Prevention Policy. By inputting the unique cryptographic hash of the file, the Falcon sensor is instructed to ignore that specific binary during scans and behavioral checks. This targeted approach prevents disruptive false positive alerts while preserving core security protections for all other unknown or malicious files across enrolled endpoints.
Question 106
What is the primary purpose of configuring Falcon Sensor Update Policy deployment rings?
- To automatically delete old user accounts every 30 days
- To stagger software updates across different host groups to test stability before global rollout
- To route web traffic through secondary proxy servers
- To schedule automated weekly hard drive backups
Correct Answer: 2
Explanation:
Sensor Update Policy deployment rings provide structured release management by allowing administrators to divide endpoints into phased rollout groups. Organizations can test new sensor builds on non-critical pilot groups first to verify application compatibility, stability, and performance before deploying updates to broader production environments. This staged approach minimizes operational risks, prevents unexpected software conflicts, and ensures seamless upgrades across heterogeneous enterprise infrastructures.
Question 107
How does Falcon Insight assist incident responders during a live forensic investigation?
- By automatically replacing broken computer hardware components
- By providing real-time process execution timelines, command-line arguments, and visual event correlation
- By rewriting local user passwords without administrator approval
- By printing physical copies of event logs on local printers
Correct Answer: 2
Explanation:
Falcon Insight serves as the core Endpoint Detection and Response (EDR) module, equipping incident responders with comprehensive visibility into endpoint telemetry. It generates detailed process execution timelines, displays exact command-line arguments, maps parent-child process trees, and correlates network connections. This deep behavioral insight allows security analysts to reconstruct attack paths, identify root causes, and scope the full extent of a security incident rapidly and accurately.
Question 108
What does the “Sensor Tampering Protection” setting prevent local users from doing?
- Changing their personal desktop wallpaper or screensaver settings
- Modifying, stopping, or uninstalling the Falcon sensor binaries and services without authorization
- Connecting personal Bluetooth headphones to their work laptops
- Accessing internal corporate email via web browsers
Correct Answer: 2
Explanation:
Sensor Tampering Protection is a critical security safeguard designed to protect the Falcon sensor’s local files, driver components, and registry keys from unauthorized modification, termination, or uninstallation. Even if a malicious actor or local user acquires high-level administrative privileges on an endpoint, this protection mechanism prevents them from disabling or removing the security agent. Authorized changes require a valid, time-sensitive maintenance token generated directly from the Falcon console.
Question 109
Which feature enables administrators to group endpoints logically based on specific criteria such as operating system or department for policy assignment?
- Firewall Zones
- Host Groups
- Sensor Repositories
- Network Subnets
Correct Answer: 2
Explanation:
Host Groups form the fundamental administrative grouping mechanism within the CrowdStrike Falcon platform. Administrators can create static or dynamic groups based on criteria such as operating system versions, organizational departments, naming conventions, or IP ranges. These groups are then used to assign tailored Prevention, Response, and Sensor Update policies, ensuring that security controls align precisely with the operational requirements of different asset categories across the enterprise.
Question 110
What is the recommended method to deploy the Falcon sensor across a large fleet of macOS endpoints using mobile device management (MDM)?
- Mailing physical installation discs to all Mac users
- Deploying the package via tools like Jamf Pro along with configuration profiles for system extensions and network filters
- Instructing users to download and compile the source code manually from public forums
- Disabling all macOS security settings before running an unverified script
Correct Answer: 2
Explanation:
Deploying the Falcon sensor across macOS environments is efficiently handled using enterprise MDM solutions such as Jamf Pro. Because modern macOS versions enforce strict security permissions regarding kernel extensions, system extensions, and network filters, administrators must package the sensor installer alongside approved MDM configuration profiles. This ensures seamless, silent installation without prompting end-users for manual security approvals, maintaining both administrative efficiency and strong endpoint protection.
Question 111
What type of event triggers a custom Fusion SOAR workflow execution?
- Routine physical office cleaning schedules
- Specific security detections, alerts, or audit events matching defined criteria
- Standard local printer queue status updates
- Employee cafeteria menu modifications
Correct Answer: 2
Explanation:
Custom Fusion SOAR workflows are triggered by specific security events, detections, or alert criteria occurring within the Falcon platform. When an event matches the configured trigger conditions—such as a high-severity malware detection, a host containment action, or an administrative policy change—the workflow engine automatically initiates the defined playbook sequence. This automation eliminates manual triage delays by executing predefined actions like sending notifications, opening ticketing system records, or isolating compromised endpoints instantly.
Question 112
What is the primary benefit of CrowdStrike’s single-agent architecture?
- Requiring a separate software installation for every individual security feature
- Providing comprehensive prevention, EDR, vulnerability management, and IT hygiene through one lightweight agent without performance degradation
- Forcing endpoints to reboot every time a configuration setting is updated
- Increasing local disk space consumption by storing multiple redundant databases
Correct Answer: 2
Explanation:
CrowdStrike’s unified single-agent architecture delivers multiple advanced security capabilities—including next-generation antivirus, EDR, vulnerability assessment, and device control—through a single, lightweight sensor installation. This design eliminates the complexity, system overhead, and driver conflicts associated with managing multiple disjointed security products. It ensures optimal endpoint performance, reduces administrative maintenance effort, and provides seamless data correlation across all security modules within the platform.
Question 113
How does Falcon Discover help organizations address shadow IT risks?
- By locking employee computer screens after five minutes of inactivity
- By continuously monitoring network traffic to identify unmanaged devices, unauthorized applications, and rogue endpoints
- By deleting unauthorized files from external USB hard drives automatically
- By encrypting all corporate email communications with a private key
Correct Answer: 2
Explanation:
Falcon Discover mitigates shadow IT risks by providing comprehensive visibility into unmanaged assets, rogue endpoints, and unauthorized applications operating within the enterprise network. By analyzing telemetry and peer observation from protected systems, Discover uncovers blind spots where security agents are missing. This visibility enables IT and security teams to enforce compliance, track asset inventory accurately, and ensure all active systems meet corporate protection standards.
Question 114
What happens when an administrator deletes a Host Group that is currently tied to an active Prevention Policy?
- All endpoints in that group are automatically uninstalled and deleted from the database
- The policy loses its target mapping, requiring administrators to reassign affected hosts to alternative groups
- The Falcon console locks up and requires a complete factory reset
- The system automatically creates a duplicate host group with default settings
Correct Answer: 2
Explanation:
When a Host Group associated with an active policy is deleted, those endpoints lose their direct policy mapping and typically fall back to the default organizational policy settings. Administrators must carefully review policy assignments before deleting host groups to ensure that sensitive servers or workstations do not inadvertently lose critical security configurations, prevention settings, or update schedules during the restructuring process.
Question 115
What is the purpose of configuring custom IOC (Indicator of Compromise) lists in Falcon IOC Management?
- To manage employee passwords and Active Directory domain controllers
- To proactively detect or block specific custom hashes, IP addresses, or domains relevant to organizational threat intelligence
- To schedule routine hardware maintenance on local servers
- To track employee attendance and working hours
Correct Answer: 2
Explanation:
Custom IOC Management allows security teams to ingest and enforce organization-specific threat intelligence by defining custom indicators such as file hashes, malicious IP addresses, or domain names. Administrators can configure these custom indicators to trigger alerts or automatically block threats across enrolled endpoints. This capability empowers organizations to act rapidly on threat briefings, industry intelligence reports, or internal incident data tailored specifically to their threat landscape.
Question 116
What is the recommended approach for investigating a high-severity detection in the Falcon console?
- Format the local hard drive immediately without looking at any logs
- Review the detection details, examine the process timeline, check related host telemetry, and assess the broader incident scope
- Disable all prevention rules and wait to see if the malware returns
- Send an email to all employees asking if they recognize the file
Correct Answer: 2
Explanation:
Investigating high-severity detections requires a structured analytical approach within the Falcon console. Analysts should begin by reviewing the core detection details, examining the process execution timeline, and checking related host telemetry to understand how the threat entered the system. Expanding the investigation via event searches and incident grouping helps determine whether the activity is isolated or part of a wider enterprise-scale adversary campaign, guiding effective remediation decisions.
Question 117
What role does CrowdStrike OverWatch play in the platform ecosystem?
- Automatically updating local Windows operating system patches every night
- Providing 24/7 managed threat hunting by elite human analysts who proactively uncover stealthy intrusions
- Managing physical office building security cameras and badge readers
- Backing up user documents to external cloud storage repositories
Correct Answer: 2
Explanation:
CrowdStrike OverWatch delivers elite, 24/7 managed threat hunting services powered by experienced security professionals. While automated sensors and machine learning models handle known threats, OverWatch experts actively analyze subtle behavioral anomalies, complex adversary techniques, and stealthy lateral movement across global telemetry streams. This human-led proactive hunting ensures that sophisticated, advanced persistent threats attempting to evade automated detection are intercepted and neutralized quickly.
Question 118
What function does the Falcon console “Trash” page serve for host management?
- It permanently deletes user account credentials every 24 hours
- It stores records of hosts that have been inactive or uninstalled for a period, pending automatic pruning after 45 days
- It collects broken hardware components shipped back from remote offices
- It acts as a staging ground for uninstalled software installers
Correct Answer: 2
Explanation:
The Trash page in the Host Management section temporarily holds records of endpoints that have been uninstalled, decommissioned, or remained inactive and failed to check in with the Falcon cloud. These records remain in the trash bin for up to 45 days before being automatically pruned and permanently removed from the console database. This retention period gives administrators a grace window to review historical asset data or restore records if systems return online unexpectedly.
Question 119
How does Falcon Firewall Management simplify enterprise security operations?
- By replacing physical corporate perimeter firewalls with software routers
- By providing centralized, cloud-based management for native host-based firewall rules across Windows and macOS endpoints
- By automatically blocking all internet traffic for all users indefinitely
- By managing local Wi-Fi router passwords for remote workers
Correct Answer: 2
Explanation:
Falcon Firewall Management centralizes host-based firewall policy creation, deployment, and auditing directly through the cloud console. Instead of manually configuring individual firewall settings on thousands of workstations, administrators can build, test, and enforce unified inbound and outbound rule sets across heterogeneous Windows and macOS endpoints. This ensures consistent network segmentation, streamlines compliance auditing, and strengthens perimeter defense capabilities directly at the host level.
Question 120
What is the primary action taken when an administrator clicks “Lift Containment” on an isolated host?
- The local operating system is completely wiped and reinstalled from scratch
- The driver-level network isolation is removed, restoring standard internal and external network connectivity to the endpoint
- The Falcon sensor uninstalls itself automatically from the machine
- The host is permanently deleted from the Host Management console inventory
Correct Answer: 2
Explanation:
Lifting containment reverses the driver-level network isolation previously applied to a compromised host during an incident response. Once remediation steps, forensic acquisitions, and threat eradication are successfully completed, administrators can lift containment via the Falcon console. This action restores standard internal network access and external internet connectivity to the workstation, allowing normal business operations to resume safely while maintaining continuous sensor telemetry monitoring.