View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 121
What is the primary function of CrowdStrike Falcon Sandbox?
- To serve as a local firewall for desktop users
- To automate user account provisioning in Active Directory
- To safely detonate and analyze suspicious files, scripts, and URLs in an isolated environment
- To backup corporate databases to external cloud storage
Correct Answer: 4
Explanation:
Falcon Sandbox provides automated malware analysis by safely detonating suspicious files, URLs, and scripts within a secure, isolated virtual environment. It observes behavioral indicators, generates detailed threat reports, and feeds threat intelligence back into the CrowdStrike ecosystem to protect endpoints from emerging threats.
Question 122
How can an administrator locate the audit history for a specific host within the Falcon console?
- By reviewing the Host Timeline and Audit Trail logs associated with that endpoint
- By reading the physical BIOS log on the motherboard
- By checking the user’s local email outbox folder
- By running a hardware diagnostic utility via USB
Correct Answer: 3
Explanation:
Administrators can investigate the lifecycle and administrative history of an endpoint by reviewing the Host Timeline and associated audit logs in the Falcon console. This provides clear visibility into when the host was registered, when policies were applied, and what containment or response actions were executed.
Question 123
What is the recommended method for handling an unresponsive endpoint that is actively spreading malware across the network?
- Send an email alert to the helpdesk team and wait for business hours
- Immediately apply Network Containment to isolate the host while maintaining cloud telemetry
- Uninstall the Falcon sensor to free up local system memory
- Disable all firewall rules to allow diagnostic troubleshooting
Correct Answer: 2
Explanation:
When an endpoint is actively compromised and threatening network integrity, placing the host into Network Containment via the Falcon console is the critical first step. Containment isolates the device at the driver level to stop lateral movement while keeping a secure connection open for incident responders.
Question 124
Which setting controls how frequently endpoints check in with the CrowdStrike cloud for policy updates and heartbeat signals?
- Cloud communication heartbeat and policy synchronization intervals managed by the platform
- Local Windows Registry color customization settings
- Hardware CPU fan speed control profiles
- External USB mouse scrolling velocity parameters
Correct Answer: 1
Explanation:
Endpoints maintain continuous situational awareness through automated heartbeat signals and policy synchronization intervals managed directly by the cloud platform, ensuring sensors receive updated configurations and threat intelligence feeds promptly.
Question 125
What is the purpose of configuring Real Time Response (RTR) audit logging?
- To track all interactive commands, script executions, and file access actions performed by analysts during RTR sessions
- To monitor physical office building electricity consumption
- To record employee cafeteria purchases and lunch schedules
- To manage software licensing expiration dates
Correct Answer: 1
Explanation:
RTR audit logging maintains a secure, detailed record of every command, script execution, and file interaction performed by security analysts during remote troubleshooting sessions, ensuring complete accountability and compliance governance.
Question 126
How does Falcon Prevent handle encrypted ransomware execution attempts on a protected host?
- It ignores the encryption process if the file extension is unrecognized
- It detects behavioral anomalies and rapid file modification patterns, automatically terminating the malicious process and blocking execution
- It prompts the user with a popup window asking if they trust the file
- It formats the local hard drive to prevent data recovery
Correct Answer: 2
Explanation:
Falcon Prevent monitors for behavioral patterns typical of ransomware, such as mass file modification and encryption attempts. When detected, the sensor immediately terminates the offending process to prevent data loss across the system.
Question 127
What is the primary benefit of using dynamic Host Groups instead of static Host Groups?
- Dynamic groups automatically add or remove endpoints based on defined criteria like naming conventions or OS versions, reducing manual administrative overhead
- Dynamic groups permanently delete endpoints after 30 days of inactivity
- Dynamic groups require manual IP address entry for every new workstation
- Dynamic groups restrict console access exclusively to system administrators
Correct Answer: 3
Explanation:
Dynamic Host Groups automatically evaluate membership criteria (such as operating system tags or hostname patterns), dynamically updating group membership without requiring manual administrator intervention as assets join or leave the network.
Question 128
Which console interface allows security teams to search historical telemetry across all endpoints using advanced query syntax?
- Event Search / Advanced Event Search
- Local Windows Notepad application
- Physical router configuration panel
- User account password reset portal
Correct Answer: 1
Explanation:
Event Search provides powerful querying capabilities that enable security analysts to hunt through historical endpoint telemetry across the entire enterprise using specialized query syntax to uncover subtle threat indicators.
Question 129
What action occurs when a custom IOA (Indicator of Attack) rule is configured with a “Block” action?
- The matching process execution is immediately terminated by the sensor before completion
- The user’s computer screen turns blue and shuts down instantly
- The file is renamed with a .bak extension and emailed to technical support
- The endpoint is permanently removed from the active inventory list
Correct Answer: 2
Explanation:
When a custom IOA rule matches malicious execution patterns and is configured to block, the Falcon sensor terminates the unauthorized process instantly, preventing the attack sequence from executing further.
Question 130
How does the Falcon platform ensure high availability and data resilience for enterprise telemetry?
- By storing all logs exclusively on local USB flash drives plugged into workstations
- By leveraging a cloud-native architecture distributed across scalable, redundant cloud infrastructure
- By printing physical paper backups of every event log daily
- By routing all data through local residential Wi-Fi routers
Correct Answer: 1
Explanation:
CrowdStrike utilizes a cloud-native architecture designed for massive scalability and resilience, securely processing and storing telemetry data across distributed, highly available cloud clusters without relying on local hardware redundancy.
Question 131
What is the role of Falcon Spotlight in identifying software vulnerabilities?
- It scans local Wi-Fi networks for weak router passwords
- It tracks application version numbers and maps them against known Common Vulnerabilities and Exposures (CVEs) in real time
- It manages employee badge access to server rooms
- It formats outdated hard drives automatically
Correct Answer: 2
Explanation:
Falcon Spotlight continuously analyzes installed software inventories on endpoints, mapping version data against active CVE databases to provide prioritized vulnerability scoring and remediation guidance without intrusive network scans.
Question 132
What is the recommended administrative practice when retiring old endpoints from the enterprise environment?
- Leave them in the active host list indefinitely without making changes
- Uninstall the sensor cleanly or allow them to age out and be pruned automatically via the Trash management lifecycle
- Format all corporate network routers immediately
- Manually edit the global database source code
Correct Answer: 3
Explanation:
When endpoints are decommissioned, administrators can let them transition through the automated cleanup lifecycle, where inactive hosts are moved to the trash bin and pruned after 45 days, keeping the asset inventory accurate.
Question 133
How does Falcon Device Control prevent unauthorized data exfiltration via removable media?
- By blocking or restricting USB mass storage devices based on customizable administrative policies
- By encrypting the physical office building doors
- By disabling all network interface cards on the computer
- By deleting all files stored in user document folders
Correct Answer: 4
Explanation:
Falcon Device Control enforces granular policies over removable media and USB storage devices, enabling security teams to block unauthorized hardware, enforce read-only access, and prevent physical data theft.
Question 134
What does a “Containment Pending” status indicate in the Host Management console?
- The isolation command has been issued from the console but has not yet been acknowledged and executed by the sensor on the target endpoint
- The endpoint has successfully completed network isolation
- The sensor has been uninstalled successfully
- The user has logged out of their Windows account
Correct Answer: 1
Explanation:
A “Containment Pending” status signifies that an administrator has requested network isolation, but the endpoint has not yet checked in to receive and execute the command, often due to temporary network latency or offline status.
Question 135
Which component of the Falcon platform aggregates disparate security alerts into a unified adversary campaign view?
- Falcon Incidents
- Local Windows Task Manager
- Printer Queue Monitor
- User Desktop Shortcut Manager
Correct Answer: 2
Explanation:
Falcon Incidents correlates multiple individual detections and related telemetry events into a single incident view, allowing analysts to understand the full scope and progression of an attacker’s campaign efficiently.
Question 136
What action should be taken if an API Client ID is compromised or exposed accidentally?
- Ignore the exposure since API keys expire automatically in one minute
- Immediately revoke the compromised API client key pair in the Falcon console and generate a new secure set
- Reboot all endpoints in the enterprise network
- Reinstall the operating system on the primary domain controller
Correct Answer: 3
Explanation:
If an API client secret or ID is compromised, administrators must revoke the credentials immediately under the API Clients and Keys menu to prevent unauthorized external access, followed by generating a new secure key pair.
Question 137
How do Sensor Update Policies help organizations maintain operational stability during major software upgrades?
- By forcing all computers to update simultaneously during peak business hours
- By allowing phased rollouts across designated host groups so updates can be validated on test systems before production deployment
- By preventing any future updates from ever occurring
- By deleting all system software files automatically
Correct Answer: 4
Explanation:
Sensor Update Policies enable phased deployment strategies, allowing organizations to test new sensor builds on controlled pilot host groups before rolling updates out to the broader production environment.
Question 138
What is the function of the Falcon console Notification Settings?
- To configure how and when alerts, detections, or system events trigger notifications via email, webhooks, or ticketing integrations
- To control the physical display brightness of user monitors
- To manage office telephone ringtones
- To update local printer driver software
Correct Answer: 1
Explanation:
Notification Settings allow administrators to configure delivery channels (such as email, webhooks, or SOAR integrations) to ensure security operations teams are alerted immediately when high-priority detections or system events occur.
Question 139
What is the primary advantage of deploying the Falcon sensor via automated enterprise tools like SCCM or Intune?
- It allows for silent, large-scale deployments across thousands of endpoints efficiently without requiring manual touchpoints
- It requires an administrator to manually log into every single physical computer
- It disables all security policies during installation
- It forces endpoints to disconnect from the internet permanently
Correct Answer: 2
Explanation:
Centralized deployment tools like SCCM, Intune, or Group Policy enable administrators to push the Falcon sensor package silently across large enterprise fleets, ensuring rapid and consistent coverage across all assets.
Question 140
How does CrowdStrike Falcon support compliance auditing for security configurations and administrative actions?
- By erasing all log history every 24 hours
- By maintaining comprehensive audit trails of console activities, policy changes, and endpoint statuses
- By restricting user access to read-only text files on local hard drives
- By disabling all reporting features in the console
Correct Answer: 3
Explanation:
Falcon maintains robust audit logging and reporting features, capturing administrative actions, policy modifications, and system statuses to satisfy regulatory compliance requirements and internal governance reviews.