View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 201
What is the primary function of CrowdStrike Falcon Discover?
- Enforcing automated operating system patches across enterprise Windows servers.
- Identifying unmanaged assets, shadow IT, and rogue devices on the network.
- Managing external firewall rule configurations for corporate perimeter routers.
- Executing remote triage scripts via Real Time Response connections.
Correct Answer: 2
Explanation:
CrowdStrike Falcon Discover is an essential IT hygiene and asset visibility module designed to help organizations uncover operational blind spots across their corporate networks. In modern enterprise environments, shadow IT, unmanaged workstations, unsupported IoT hardware, and rogue endpoints frequently connect to corporate subnets without proper security controls or endpoint agents installed. Falcon Discover leverages passive network traffic analysis and peer observation from already-protected endpoints to continuously map active network assets. By comparing observed devices against registered Falcon sensor databases, Discover highlights unmanaged coverage gaps, provides detailed asset inventory reports, and enables security teams to enforce mandatory agent deployment across all active organizational systems, ensuring comprehensive enterprise visibility and robust defensive posture management.
Question 202
How does Falcon Firewall Management handle host-based network rules?
- By replacing corporate perimeter hardware firewalls with cloud software routers.
- By automatically blocking all incoming web traffic for remote workers.
- By routing local printer data through encrypted virtual private networks.
- By providing centralized cloud management for native host firewall rules.
Correct Answer: 4
Explanation:
Falcon Firewall Management centralizes the creation, deployment, auditing, and enforcement of native host-based firewall policies across heterogeneous Windows and macOS operating systems directly through the CrowdStrike cloud console. Instead of requiring administrators to manually configure individual firewall rules on thousands of disparate endpoints using native operating system tools or complex scripts, Firewall Management provides a unified interface. Administrators can define precise inbound and outbound rule sets, establish network zone profiles, and apply policies dynamically based on host groups. This ensures consistent network segmentation, streamlines regulatory compliance auditing, and strengthens perimeter defense capabilities directly at the host level, regardless of whether endpoints are connected to the corporate office network or operating remotely over public internet connections.
Question 203
Which console feature logs administrative changes and user logins?
- Falcon UI Audit Trail
- Sensor Download Repository
- Host Management Trash Bin
- Fusion Workflow Execution Log
Correct Answer: 1
Explanation:
The Falcon UI Audit Trail serves as an immutable, comprehensive governance tool within the CrowdStrike Falcon platform, capturing a chronological record of all administrative activities performed inside the cloud console. This includes tracking user authentication events, session logins, policy modifications, custom exclusion creation, containment commands issued, and role-based access control alterations. The audit trail provides vital accountability and visibility, ensuring that security leadership can review exactly who made specific configuration changes, what parameters were modified, and when those alterations occurred. This capability is crucial for meeting rigorous regulatory compliance mandates, satisfying internal security governance frameworks, and investigating unauthorized or unexpected modifications to enterprise security postures.
Question 204
What does a pending host registration status typically indicate?
- The endpoint has been permanently isolated via network containment.
- The local operating system hard drive has failed completely.
- The sensor has been installed but has not yet checked in.
- The endpoint license has expired and all protections are disabled.
Correct Answer: 3
Explanation:
A “Pending” status in the Host Management console view typically appears immediately following a fresh sensor deployment when the agent has been installed onto the operating system file structure, but has not yet completed its initial handshake, configuration handshake, or telemetry check-in with the CrowdStrike cloud infrastructure. This temporary state usually resolves itself automatically once the endpoint establishes active internet connectivity, validates its Customer ID (CID) installation parameter, and begins streaming initial system events. If a host remains in a pending state indefinitely, it usually indicates underlying network connectivity barriers, firewall blocking outbound HTTPS traffic to CrowdStrike cloud endpoints, or improper installation parameter configuration during deployment.
Question 205
How are sensor update deployment rings utilized by administrators?
- To automatically delete old inactive user accounts every thirty days.
- To stagger software updates across groups to test stability.
- To route web browsing traffic through secondary proxy servers.
- To schedule automated weekly hard drive storage backups.
Correct Answer: 2
Explanation:
Sensor Update Policy deployment rings provide structured release management by allowing administrators to divide enterprise endpoints into phased rollout groups. Rather than deploying new sensor builds globally all at once—which carries the risk of unexpected software conflicts or operational disruption—organizations can assign pilot sensor versions to non-critical test host groups first. This enables IT and security teams to evaluate software compatibility, driver stability, and performance metrics in a controlled environment. Once stability is verified, administrators can advance the update policy to broader production rings. This staged deployment methodology minimizes operational risk and ensures seamless software lifecycle management across complex enterprise infrastructures.
Question 206
What capability does Falcon OverWatch provide to enterprise networks?
- Automated operating system patch deployment tracking for Windows servers.
- Cloud Security Posture Management across multi-cloud infrastructure environments.
- Real-time file integrity monitoring for regulatory compliance auditing.
- Elite 24/7 managed threat hunting powered by human experts.
Correct Answer: 4
Explanation:
Falcon OverWatch is CrowdStrike’s premier managed threat hunting service, pairing advanced cloud telemetry analytics with elite human threat hunters who actively analyze subtle behavioral anomalies and complex adversary techniques around the clock. While automated sensors and machine learning models excel at intercepting known malware and standard attacks, sophisticated adversaries frequently employ stealthy, fileless tactics, living-off-the-land binaries, and stolen credentials to blend into normal administrative activity. OverWatch experts continuously hunt across global telemetry streams to uncover these advanced persistent threats that automated defenses might otherwise miss, alerting organizations and intercepting intrusions before catastrophic data exfiltration or ransomware deployment can occur.
Question 207
Which module provides cloud security posture management capabilities?
- Falcon Horizon
- Falcon Prevent
- Falcon Insight
- Falcon Discover
Correct Answer: 1
Explanation:
Falcon Horizon provides comprehensive Cloud Security Posture Management (CSPM) across major multi-cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). Horizon continuously monitors cloud resource configurations, identifies security misconfigurations, checks compliance adherence against established industry frameworks, and detects infrastructure vulnerabilities. By providing deep visibility into cloud-native architectures, container services, and identity permissions, Horizon helps security operations teams maintain a secure cloud posture, prevent unauthorized data exposure, and remediate misconfigurations before malicious actors can exploit them in complex multi-cloud deployments.
Question 208
What is the purpose of custom IOA exclusion rules?
- Blocking unauthorized network traffic from external malicious IP addresses.
- Encrypting local hard drives during initial operating system installation.
- Preventing behavioral rules from flagging authorized administrative scripts.
- Deleting temporary installation cache files to save disk space.
Correct Answer: 3
Explanation:
Custom Indicator of Attack (IOA) Exclusions are specifically engineered to prevent behavioral detection rules from falsely flagging authorized administrative scripts, proprietary deployment tools, or internal automation tasks as malicious. In many enterprise environments, legitimate administrative utilities execute complex command-line arguments or process behaviors that resemble adversary techniques. By specifying precise parameters—such as exact parent processes, command-line wildcards, or file execution paths—administrators can suppress false positives for trusted custom software without compromising overall endpoint security posture or disabling underlying core protection features across enrolled systems.
Question 209
How does Falcon Device Control mitigate removable media risks?
- By reformatting infected hard drives automatically during system reboots.
- By blocking or restricting USB mass storage devices via policies.
- By deleting all files stored inside local user document directories.
- By disabling all network interface cards on the workstation computer.
Correct Answer: 2
Explanation:
Falcon Device Control empowers organizations to prevent data exfiltration and insider threats by enforcing granular administrative policies over removable media and USB storage hardware. Security teams can configure rules to block unauthorized USB mass storage devices entirely, enforce strict read-only access to prevent file copying onto unapproved flash drives, or whitelist specific corporate-issued encrypted drives. This targeted control stops physical data theft at the endpoint level without disrupting standard peripheral usage like authorized keyboards, mice, or enterprise smart card readers, ensuring balanced productivity and security.
Question 210
What role do Sensor Maintenance Tokens serve during updates?
- Generating automated API authentication keys for external SOAR integrations.
- Extending enterprise software licensing expiration dates for platforms.
- Automatically resetting forgotten user account passwords in Active Directory.
- Allowing authorized uninstallation or modification when tampering protection is active.
Correct Answer: 4
Explanation:
Sensor Maintenance Tokens work in tandem with Sensor Tampering Protection to safeguard the Falcon sensor’s local files, driver components, and registry keys from unauthorized modification, termination, or uninstallation. When Tampering Protection is enabled, local users—even those possessing high-level local administrator privileges on the endpoint—cannot uninstall, disable, or repair the sensor without providing a unique, time-sensitive maintenance token generated directly from the Falcon console by an authorized administrator. This prevents malicious actors or compromised service accounts from stripping away security controls during an intrusion campaign.
Question 211
Which component streams raw kernel telemetry to cloud platforms?
- Falcon Sensor
- Falcon Console GUI
- Fusion SOAR Engine
- Threat Graph Database
Correct Answer: 1
Explanation:
The Falcon sensor is an advanced, lightweight agent installed directly onto endpoints to monitor operating system activity in real time. Operating seamlessly at both the kernel and user levels, the sensor captures comprehensive process creation events, file modifications, network connections, and registry changes without impacting system performance. This raw telemetry is processed locally and streamed securely to the cloud platform, forming the foundational data layer required for behavioral analysis, threat detection, incident investigation, and real-time correlation across the CrowdStrike ecosystem.
Question 212
How do custom Hash Exclusions affect local sensor scanning?
- Forcing endpoints to reboot immediately upon file execution completion.
- Automatically quarantining all files matching specified file extensions.
- Instructing the sensor to bypass detection for specific file hashes.
- Blocking all network connections associated with a specific malicious IP.
Correct Answer: 3
Explanation:
A custom Hash Exclusion instructs the Falcon sensor to bypass detection, prevention, and behavioral scrutiny for a specific file based on its unique cryptographic hash (such as SHA-256). This administrative setting is useful when an internal proprietary tool, custom software utility, or specialized legacy application is incorrectly flagged as a false positive by machine learning or signature checks. Applying a hash exclusion allows the trusted binary to execute freely across enrolled endpoints without triggering alerts or automated blocks, restoring business operability while maintaining security coverage for unknown files.
Question 213
What action does network containment perform on compromised hosts?
- Deleting all local user account credentials and profile folders.
- Isolating the device at the driver level to stop lateral movement.
- Uninstalling the local security sensor to reclaim system memory.
- Disabling all local firewall rules to permit remote forensic analysis.
Correct Answer: 2
Explanation:
When an endpoint is actively compromised and threatens network integrity, placing the host into Network Containment isolates the device instantly at the driver level. This containment action severs unauthorized internal peer-to-peer connections, lateral movement channels, and public internet access, effectively trapping the threat on the machine and preventing data exfiltration or worm propagation across the enterprise. Crucially, a secure, encrypted communication pipe remains open exclusively between the Falcon sensor and the CrowdStrike cloud platform, ensuring that incident responders retain remote access to investigate, retrieve forensic packages, and lift containment when remediation is complete.
Question 214
Which Falcon module handles real-time file integrity monitoring?
- Falcon Spotlight
- Falcon Discover
- Falcon Horizon
- Falcon FileVantage
Correct Answer: 4
Explanation:
Falcon FileVantage provides robust file integrity monitoring (FIM) capabilities across enterprise endpoints, enabling organizations to track, audit, and log real-time modifications, creations, and deletions of critical system files, configuration settings, and registry paths. FileVantage is essential for maintaining regulatory compliance across frameworks that mandate strict change tracking (such as PCI-DSS and HIPAA). By alerting security teams immediately to unauthorized alterations or unexpected persistence mechanisms, FileVantage helps organizations detect system tampering and zero-day modifications instantly.
Question 215
How are API clients configured for external tool authentication?
- Generating client ID and secret pairs with assigned OAuth scopes.
- Typing plaintext administrator passwords into local Windows configuration files.
- Copying physical hardware security keys into corporate router USB ports.
- Setting up shared email distribution lists for automated alert delivery.
Correct Answer: 1
Explanation:
API Clients and Keys enable authorized external applications, security information and event management (SIEM) platforms, orchestration tools, and custom automation scripts to authenticate securely with CrowdStrike Falcon REST APIs. Administrators configure these integrations by generating dedicated client ID and secret pairs, assigning specific OAuth scopes and permissions that adhere to the principle of least privilege. This ensures that external integrations can programmatically pull telemetry, manage host data, and submit queries without exposing master administrative console credentials.
Question 216
What function do custom IOC management lists perform globally?
- Managing employee password expiration schedules in Active Directory.
- Scheduling routine hardware maintenance windows on local servers.
- Proactively detecting or blocking specific custom hashes, IPs, or domains.
- Tracking employee cafeteria attendance and working hours daily.
Correct Answer: 3
Explanation:
Custom IOC Management allows security teams to ingest and enforce organization-specific threat intelligence by defining custom indicators such as file hashes, malicious IP addresses, or domain names. Administrators can configure these custom indicators to trigger alerts or automatically block threats across enrolled endpoints. This capability empowers organizations to act rapidly on threat briefings, industry intelligence reports, or internal incident data tailored specifically to their unique threat landscape, augmenting out-of-the-box detection models.
Question 217
Which interface provides deep historical endpoint telemetry search tools?
- Local Windows Notepad text document editing application.
- Advanced Event Search and historical telemetry querying console.
- Physical network router hardware administrative configuration panel.
- Enterprise user account password reset web portal interface.
Correct Answer: 2
Explanation:
The Advanced Event Search interface provides security analysts and threat hunters with powerful querying capabilities to inspect historical endpoint telemetry across the entire enterprise. By leveraging specialized query syntax, analysts can search through billions of recorded events—including process executions, network connections, file modifications, registry changes, and user logons—to hunt for subtle indicators of compromise, trace attack paths, and investigate security incidents. This cloud-scale search capability transforms raw sensor data into actionable intelligence, enabling rapid root-cause analysis and comprehensive threat scoping.
Question 218
What does sensor tampering protection prevent local users from?
- Changing their personal desktop wallpaper or screensaver settings.
- Connecting personal Bluetooth headphones to their work laptops.
- Accessing internal corporate email via web browser applications.
- Modifying, stopping, or uninstalling Falcon sensor binaries and services.
Correct Answer: 4
Explanation:
Sensor Tampering Protection is a critical security safeguard designed to protect the Falcon sensor’s local files, driver components, and registry keys from unauthorized modification, termination, or uninstallation. Even if a malicious actor or local user acquires high-level administrative privileges on an endpoint, this protection mechanism prevents them from disabling or removing the security agent. Authorized changes or uninstallation procedures require a valid, time-sensitive maintenance token generated directly from the Falcon console by an administrator, ensuring the agent remains active and resilient against tampering attacks.
Question 219
How does Falcon Spotlight assess operating system software vulnerabilities?
- Mapping installed software inventories against known CVEs in real time.
- Scanning local Wi-Fi router networks for weak default passwords.
- Formatting outdated local hard drives automatically during maintenance.
- Managing employee physical security badge access to server rooms.
Correct Answer: 1
Explanation:
Falcon Spotlight redefines vulnerability management by eliminating resource-intensive, intrusive network scanners that strain corporate bandwidth and server stability. Because the lightweight Falcon sensor already possesses deep visibility into operating system kernels and installed software inventories, Spotlight continuously maps application version data against active Common Vulnerabilities and Exposures (CVE) databases in real time. This provides security and IT teams with prioritized vulnerability scoring, contextual exploit intelligence, and actionable remediation guidance directly from the Falcon console, streamlining patch management workflows.
Question 220
What trigger types initiate automated Fusion SOAR workflow execution?
- Routine physical office building cleaning and maintenance schedules.
- Standard local printer queue status updates and paper jams.
- Specific security detections, alerts, or audit events matching criteria.
- Employee cafeteria menu modifications and catering requests.
Correct Answer: 3
Explanation:
Custom Fusion SOAR workflows are triggered by specific security events, detections, alert criteria, or audit log entries occurring within the Falcon platform. When an incoming event matches the configured trigger conditions—such as a high-severity malware detection, a host containment action, or an administrative policy change—the workflow engine automatically initiates the defined playbook sequence. This automation eliminates manual triage delays by executing predefined actions like sending notifications to collaboration tools, opening IT service management ticketing records, or isolating compromised endpoints instantly.