View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 301
Where can administrators review historical execution logs of Fusion workflows?
- Local Windows Event Viewer security logs on endpoints.
- The Fusion Workflow Execution History tab in the console.
- The physical router hardware administrative dashboard.
- User browser cache history folders.
Correct Answer: 2
Explanation:
Administrators can audit and review the performance, success rates, and execution details of automated playbooks by navigating to the Fusion Workflow Execution History tab within the Falcon console. This interface provides detailed logging for every workflow run, including input parameters, step-by-step execution states, and any error messages encountered during automated task processing, facilitating effective troubleshooting and operational oversight.
Question 302
What role does the Falcon Discover module play regarding corporate IoT devices?
- Enforcing automatic BIOS password updates across routers.
- Encrypting local storage drives on smart appliances.
- Uncovering unmanaged and rogue hardware connected to the network.
- Managing software licensing expiration dates for servers.
Correct Answer: 3
Explanation:
Falcon Discover enhances enterprise visibility by identifying unmanaged assets, shadow IT, unsupported IoT hardware, and rogue devices connected to the corporate network. By leveraging passive network traffic analysis and peer observation from protected endpoints, Discover highlights coverage gaps, helps security teams enforce agent deployment, and ensures complete enterprise visibility across all active organizational systems without requiring intrusive network scanners.
Question 303
How does Falcon Prevent leverage machine learning on endpoints?
- Analyzing local file features and behavioral heuristics both offline and online.
- Prompting users to approve every unknown file execution via popups.
- Running intrusive full-disk scans every night at midnight.
- Deleting files that have not been opened for thirty days.
Correct Answer: 1
Explanation:
Falcon Prevent utilizes advanced machine learning models embedded directly within the lightweight sensor to evaluate file characteristics and behavioral heuristics in real time. These models operate effectively both online and offline, enabling the sensor to identify and block malicious binaries, ransomware, and zero-day threats instantly at the moment of execution without needing to consult cloud databases for every single file check.
Question 304
What specific permission is required to run administrative scripts via Real Time Response?
- Global administrator console password credentials.
- Local Windows domain controller administrator rights.
- Physical access to the workstation keyboard and mouse.
- RTR script execution privileges defined within custom Response Policies.
Correct Answer: 4
Explanation:
Real Time Response (RTR) capabilities are governed by granular Response Policies that control feature access and execution rights across different host groups. To run administrative scripts or execute remediation commands on remote endpoints, analysts must be assigned the appropriate RTR permissions within their user role and be operating under a policy configuration that permits active script execution for the targeted host group, ensuring strict operational governance.
Question 305
Why would an administrator use a Sensor Maintenance Token?
- To automatically renew software licensing contracts with CrowdStrike.
- To bypass Tampering Protection for authorized uninstallation or repairs.
- To generate API authentication secrets for SIEM integrations.
- To extend the offline telemetry caching period indefinitely.
Correct Answer: 2
Explanation:
Sensor Maintenance Tokens work alongside Tampering Protection to prevent unauthorized sensor uninstallation or modification. When Tampering Protection is enabled, local users and administrators cannot uninstall or repair the sensor without providing a unique, time-sensitive maintenance token generated directly from the Falcon console by an authorized administrator, ensuring the agent remains active and resilient against tampering attacks.
Question 306
What does the Falcon Spotlight vulnerability dashboard prioritize?
- File sizes and disk space consumption across workstations.
- Network cable connection speeds and router throughput.
- CVE remediation based on active exploitability and asset criticality.
- Employee login frequency and active session durations.
Correct Answer: 3
Explanation:
Falcon Spotlight revolutionizes vulnerability management by providing prioritized risk scoring based on active exploitability, threat intelligence context, and asset criticality. Rather than presenting security teams with an unmanageable list of all unpatched CVEs, Spotlight highlights which vulnerabilities are actively being exploited in the wild and which affected assets represent the highest operational risk, enabling efficient and targeted remediation workflows.
Question 307
How does the Falcon sensor handle network connectivity loss?
- Caching telemetry events locally in a secure ring-buffer on disk.
- Deleting all accumulated event logs immediately to save memory.
- Shutting down the operating system to prevent security exposure.
- Switching automatically to an unencrypted public Wi-Fi hotspot.
Correct Answer: 1
Explanation:
The Falcon sensor is engineered to operate seamlessly during network disruptions. When an endpoint loses connection to the CrowdStrike cloud, the sensor caches telemetry locally in a secure, ring-buffered storage area on disk. Once internet connectivity is re-established, the sensor securely uploads the buffered events to the cloud for processing, ensuring that security teams retain historical visibility without losing critical operational event logs.
Question 308
What is a key characteristic of static Host Groups?
- Automatic membership updates based on operating system tags.
- Dynamic addition of endpoints based on IP address ranges.
- Automatic removal of hosts after thirty days of inactivity.
- Manual inclusion and exclusion of specific endpoints by administrators.
Correct Answer: 4
Explanation:
Static Host Groups require manual administrator intervention to add or remove specific endpoints. Unlike dynamic groups that evaluate membership rules automatically based on tags, naming conventions, or IP ranges, static groups provide precise, fixed administrative control over a defined list of machines, making them useful for specialized testing groups or static server clusters that require unchanging policy assignments.
Question 309
What is the function of the Falcon API rate limiting mechanism?
- Controlling the physical network bandwidth consumption of endpoints.
- Protecting cloud infrastructure from excessive API request floods.
- Limiting how many users can log into the Falcon console simultaneously.
- Regulating local CPU usage during antivirus scans.
Correct Answer: 2
Explanation:
Falcon API rate limiting protects the cloud platform’s infrastructure and ensures high availability for all customers by regulating the volume of REST API requests permitted from any single client ID within a given timeframe. If an integration script exceeds the configured threshold, the API returns a rate limit response, prompting the client application to back off and retry after a specified interval, preventing service degradation.
Question 310
How does Falcon Horizon assist cloud security teams?
- By blocking unauthorized USB flash drives on remote laptops.
- By managing local printer drivers and print queues.
- By monitoring cloud resource misconfigurations and compliance posture.
- By automating Windows operating system patch deployments.
Correct Answer: 3
Explanation:
Falcon Horizon provides Cloud Security Posture Management (CSPM) across major cloud service providers (such as AWS, Azure, and GCP). It continuously monitors cloud resource configurations, identifies security misconfigurations, detects compliance violations, and uncovers infrastructure vulnerabilities, helping security teams maintain a secure cloud posture and prevent unauthorized data exposure in complex multi-cloud environments.
Question 311
What type of event triggers a custom Indicator of Compromise (IOC) alert?
- A match against defined custom file hashes, IP addresses, or domains.
- A normal user logging into their Windows workstation account.
- A scheduled system backup completing successfully.
- A standard browser application launching during business hours.
Correct Answer: 1
Explanation:
Custom IOC Management allows security teams to ingest and enforce organization-specific threat intelligence by defining custom indicators such as file hashes, malicious IP addresses, or domain names. When telemetry streams from endpoints match these specific custom indicators, the Falcon platform triggers alerts or blocks, empowering organizations to act rapidly on threat briefings and intelligence reports tailored to their unique threat landscape.
Question 312
What does the Host Details page display regarding installed applications?
- Physical hardware warranty expiration dates and vendor support phone numbers.
- Local office building electricity consumption and power usage grids.
- Employee cafeteria lunch schedules and corporate catering menus.
- An inventory of software packages and installed programs for vulnerability assessment.
Correct Answer: 4
Explanation:
The Host Details page in the Falcon console provides comprehensive visibility into individual endpoints, including an exhaustive inventory of installed software applications, operating system details, network configurations, active user sessions, and associated vulnerability data. This detailed application inventory empowers security and IT teams to review installed software versions, assess security posture, and support vulnerability management workflows directly within the platform.
Question 313
What is the primary purpose of Falcon Fusion SOAR playbook triggers?
- Scheduling routine weekly workstation reboots during maintenance windows.
- Automatically initiating automated workflow execution when specific event conditions are met.
- Managing corporate software licensing inventories and vendor contract renewals.
- Formatting local storage drives automatically upon threat detection.
Correct Answer: 2
Explanation:
Falcon Fusion SOAR playbook triggers serve as the starting point for automated security workflows within the CrowdStrike Falcon platform. When an incoming event, detection, alert, or audit log entry matches the predefined trigger criteria—such as a high-severity malware alert, a host containment action, or a policy modification—the workflow engine automatically initiates the associated playbook sequence. This automation eliminates manual triage delays by executing predefined response actions, streamlining operations, and accelerating incident resolution across enterprise security teams.
Question 214
How does Falcon Identity Protection handle compromised Active Directory credentials?
- By forcing all domain controllers to shut down immediately.
- By resetting every corporate user password every twelve hours.
- By detecting real-time anomalies and blocking unauthorized authentication requests.
- By deleting all user profile folders from local workstations.
Correct Answer: 3
Explanation:
Falcon Identity Protection focuses specifically on defending enterprise identity infrastructure by monitoring Active Directory activities, credential usage, and authentication requests in real time. When anomalous authentication patterns, brute-force attempts, or compromised credentials are detected across hybrid environments, Identity Protection can dynamically challenge users, step up authentication requirements, or block unauthorized authentication requests before attackers can leverage stolen credentials for lateral movement.
Question 315
What action does Falcon Insight provide to security analysts during an active threat investigation?
- Continuous recording and streaming of detailed endpoint telemetry for deep behavioral visibility.
- Automated physical door lock activation in corporate server rooms.
- Deletion of all temporary internet cache files on workstations.
- Routing of local network print jobs through secondary proxy servers.
Correct Answer: 1
Explanation:
Falcon Insight provides Endpoint Detection and Response (EDR) capabilities by continuously recording and streaming rich, granular endpoint telemetry to the CrowdStrike Threat Graph. This gives security analysts deep behavioral visibility into process executions, file modifications, network connections, and registry changes. During an active threat investigation, analysts can review this historical telemetry to trace attack paths, identify root causes, and understand the full scope of an intrusion across the enterprise.
Question 316
When configuring a Sensor Update Policy, what does setting a deferred version achieve?
- It forces endpoints to uninstall the security sensor entirely.
- It accelerates sensor updates to deploy within seconds of release.
- It disables all telemetry streaming to the cloud platform.
- It holds back specific sensor versions to ensure compatibility testing is completed.
Correct Answer: 4
Explanation:
Deferred sensor update settings allow administrators to hold back specific sensor builds or delay automatic upgrades across designated host groups. This staged approach ensures that IT and security teams have sufficient time to validate software compatibility with proprietary line-of-business applications and internal drivers before rolling new sensor versions into production. By controlling update velocity, organizations prevent unexpected operational disruptions and maintain system stability.
Question 317
What is required to successfully install the Falcon sensor on a Windows endpoint?
- A physical hardware security dongle plugged into a USB port.
- The unique Customer ID (CID) installation parameter string.
- The personal administrator password of the end-user.
- An active subscription to third-party antivirus software.
Correct Answer: 2
Explanation:
Every CrowdStrike Falcon sensor deployment requires the unique Customer ID (CID) string to associate the installed agent with the correct organizational tenant in the cloud. During manual installations, deployment scripts, or centralized enterprise push deployments (via SCCM or Intune), passing the CID parameter ensures that telemetry and security events are correctly routed to the organization’s Falcon console.
Question 318
What function does the Falcon console Trash management page serve?
- It stores deleted email notification templates and webhooks.
- It collects temporary installation cache files from remote endpoints.
- It holds decommissioned and inactive hosts before permanent pruning.
- It archives old administrator password hashes for compliance auditing.
Correct Answer: 3
Explanation:
The Trash management page in the Falcon console acts as a holding area for endpoints that have been deleted or have exceeded inactivity thresholds. When systems are decommissioned or replaced, they transition through automated cleanup workflows into the trash bin, where they remain accessible for administrative review for a defined retention window before being permanently pruned after 45 days. This keeps active host inventories clean while preventing accidental data loss.
Question 319
How does a Custom IOA rule differ from a traditional file hash match?
- It evaluates dynamic process behavior, command-line arguments, and parent-child trees.
- It only checks file sizes and physical creation timestamps.
- It requires manual user approval before blocking execution.
- It only functions when the endpoint is completely offline.
Correct Answer: 1
Explanation:
While static hash matching relies on a known cryptographic signature of a specific file, Custom Indicators of Attack (IOA) evaluate dynamic execution behaviors, parent-child process relationships, and command-line arguments in real time. This behavioral approach allows security teams to detect and block malicious activity even when attackers use legitimate living-off-the-land binaries, modified scripts, or novel zero-day payloads that lack known static signatures.
Question 320
What is the primary function of Falcon Fusion workflow action blocks?
- Rendering graphical user interface color themes for console users.
- Controlling physical office lighting and temperature systems.
- Managing local Windows registry color customization settings.
- Executing automated tasks like sending webhooks, creating tickets, or isolating hosts.
Correct Answer: 4
Explanation:
Action blocks within Falcon Fusion workflows define the automated tasks that execute when a trigger condition is met and filtered successfully. Administrators can configure action blocks to perform various response tasks automatically, such as isolating a compromised host, sending alert notifications via webhooks or email, creating incident tickets in ITSM platforms, or initiating forensic package collections without requiring manual analyst intervention.