View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 21
If a user wanted to install an older version of the Falcon sensor, how would they find the older installer file?
- Contact CrowdStrike Support via a priority ticket
- Click on the “Older versions” links below each sensor download button
- Run an automatic CLI downgrade command
- Check the software repository under the global settings menu
Correct Answer: 2
Explanation:
If you need to install or deploy an older version of the Falcon sensor for compatibility testing, specific application requirements, or controlled environment rollouts, you can easily locate and access previous builds within the console interface. Simply navigate to the sensor download section and click on the “Older versions” links found directly below each respective sensor download button. This opens a dedicated historical view allowing administrators to select, download, and deploy past sensor packages safely without needing to contact technical support.
Question 22
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
- Custom Alert History
- Workflow Execution log
- Workflow Audit log
- Falcon UI Audit Trail
Correct Answer: 2
Explanation:
When automated Fusion SOAR workflows fail to deliver notifications or execute actions as expected, the Workflow Execution log within the Workflow Management options is the primary location to inspect for troubleshooting. It provides administrators with detailed visibility into past workflow runs, allowing them to review the status, operational results, specific triggers, payload outputs, and any encountered system errors. Analyzing these logs helps pinpoint misconfigured conditions, integration timeouts, or syntax issues preventing successful event processing.
Question 23
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
- Endpoint ID (EID)
- Agent ID (AID)
- Security ID (SID)
- Computer ID (CID)
Correct Answer: 2
Explanation:
The Agent ID (AID) is a unique alphanumeric identifier generated and assigned to each individual endpoint sensor upon successful installation and initial registration with the CrowdStrike cloud platform. The AID acts as the core reference token for tracking telemetry, mapping device history, correlating behavioral events, and issuing targeted commands through Real Time Response. Every unique operating system instance maintains its own distinct AID, which remains vital for inventory management, API integrations, and forensic investigations across the enterprise environment.
Question 24
Once an exclusion is saved, what elements can be edited in the future?
- All parts of the exclusion can be changed
- Only the selected groups and hosts to which the exclusion is applied can be changed
- Only the options to “Detect/Block” and/or “File Extraction” can be changed
- The exclusion pattern and syntax cannot be changed under any circumstance
Correct Answer: 2
Explanation:
Once a prevention exclusion has been successfully created and saved in the Falcon console, core parameters such as the exclusion pattern, file path syntax, or file hash cannot be freely modified to maintain strict administrative governance and security integrity. If path rules or conditions need to be altered, administrators must create a brand-new exclusion. Consequently, the only editable elements downstream are the assigned host groups or organizational scope to which the existing exclusion applies.
Question 25
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?
- Edit the Default Response Policy, toggle the “Real Time Response” switch off and assign the policy to the host group
- Edit the Default Response Policy and add the host group to the exceptions list under “Real Time Functionality”
- Create a new Response Policy, toggle the “Real Time Response” switch off and assign the policy to the host group
- Create a new Response Policy and add the host name to the exceptions list under “Real Time Functionality”
Correct Answer: 3
Explanation:
To cleanly restrict Real Time Response (RTR) functionality for specific sensitive assets without impacting the entire enterprise security posture, administrators must create a dedicated custom Response Policy. Within this custom policy, toggle the Real Time Response feature to the off position, and then scope or assign that policy directly to the target host group containing those restricted servers. This ensures compliance with internal governance rules while preserving standard operational policies for all other unrestrictive systems.
Question 26
Which exclusion pattern will prevent detections on a file located at C:\Program Files\My Program\My Files\program.exe?
- Program Files\My Program\My Files\
- Program Files\My Program\*
- *\Program Files\My Program\*
- *Program Files\My Program*
Correct Answer: 2
Explanation:
Using wildcard directory patterns like Program Files\My Program\* correctly targets the specific file path structure and all underlying child elements to prevent unwanted detections or blocks on legitimate internal applications residing within that directory. Properly structuring wildcard exclusions ensures that security controls do not interfere with internal software functionality while minimizing security blind spots. It isolates the exception to the intended software folder rather than granting overly broad system-wide permissions.
Question 27
Why is the ability to temporarily disable detections on a host helpful?
- It gives users the ability to set up hosts to test detections and later remove them from the console
- It gives users the ability to uninstall the sensor from a host
- It gives users the ability to allowlist a false positive detection
- It gives users the ability to remove all telemetry data from uninstalled hosts
Correct Answer: 3
Explanation:
The ability to temporarily disable detections on an individual endpoint provides administrators, developers, and security analysts with a structured way to troubleshoot, isolate, and safely evaluate software behavior. It is especially useful when investigating potential false positive detections or testing specialized application deployment workflows without permanent policy changes. This temporary suspension allows teams to observe live system telemetry and application performance under active conditions before deciding whether to implement permanent exclusions.
Question 28
What impact does disabling detections on a host have on the Falcon API telemetry stream?
- Endpoints with detections disabled will not alert on anything until detections are enabled again
- Endpoints cannot have their detections disabled individually
- DetectionSummaryEvent stops sending to the Streaming API for that host
- Endpoints with detections disabled will stop logging completely for 24 hours
Correct Answer: 1
Explanation:
When detections are temporarily disabled for a target endpoint, the sensor suppresses all security alerts entirely. This means the system will continue to record routine telemetry but will not trigger, surface, or transmit detection events for blocklists, machine learning models, or Indicators of Attack (IOAs) until the feature is re-enabled. Administrators must exercise caution with this setting, as it intentionally blinds the console to active threats on that device during the maintenance window.
Question 29
What is the correct role that can be added to fulfill a requirement where Falcon Analysts need to view files and file contents locally on compromised hosts, but without the ability to extract or download them off the host?
- Remediation Manager
- Real Time Responder – Read Only Analyst
- Falcon Analyst – Read Only
- Real Time Responder – Active Responder
Correct Answer: 2
Explanation:
The “Real Time Responder – Read Only Analyst” role allows team members to securely connect to endpoints via Real Time Response to inspect files, view directory contents, and run read-only diagnostic commands. Crucially, it enforces security boundaries by omitting full administrative remediation privileges or file extraction capabilities. This ensures junior analysts or auditors can perform necessary investigations and gather contextual forensic artifacts without risking unauthorized data exfiltration or file removal from compromised systems.
Question 30
All development work is required to be stored on a file share in a folder called “devcode.” What setting can you use to reduce false positives on this specific file path?
- USB Device Policy
- Firewall Rule Group
- Containment Policy
- Machine Learning Exclusions
Correct Answer: 4
Explanation:
Machine Learning Exclusions allow administrators to configure specialized GLOB expressions, file path exemptions, and directory rules so that custom code development environments and repositories like “devcode” do not constantly trigger unwanted machine learning blocks. Because frequent code compilation and rapid prototyping often mimic heuristic behavioral patterns associated with malware, path-based machine learning exclusions ensure development workflows continue smoothly without bombarding security operations teams with repetitive false positive alerts.
Question 31
On which page of the Falcon console can an administrator locate the Customer ID (CID)?
- Hosts Management
- API Clients and Keys
- Sensor Dashboard
- Sensor Downloads
Correct Answer: 2
Explanation:
The Customer ID (CID), which acts as the unique organizational identifier required for successful sensor installation, environment configuration, and external API authentication, is prominently displayed directly at the top of the API Clients and Keys management page within the Falcon console. Administrators frequently reference this specific string when scripting automated mass deployments, configuring third-party SIEM integrations, or validating installation parameters across various operating systems.
Question 32
What feature should be disabled on perimeter firewalls so that the sensor’s man-in-the-middle attack protection works properly?
- Deep packet inspection
- Linux Sub-System
- PowerShell execution policy
- Windows Proxy mapping
Correct Answer: 1
Explanation:
Deep packet inspection (DPI) and SSL/TLS interception features on corporate perimeter firewalls can alter network traffic, strip headers, or re-sign security certificates. This administrative behavior actively interferes with the Falcon sensor’s hard-coded certificate validation mechanisms and secure pinning logic used to maintain encrypted communication channels with the CrowdStrike cloud. Disabling DPI for sensor traffic ensures telemetry streams securely without triggering connection drops or false security faults.
Question 33
An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?
- 75 Days
- 60 Days
- 90 Days
- 45 Days
Correct Answer: 4
Explanation:
Hosts that remain completely inactive, decommissioned, or permanently disconnected and fail to check in with the CrowdStrike cloud infrastructure are automatically pruned from active console views and the system trash bin after exactly 45 days. This automated lifecycle cleanup prevents stale virtual machines, retired laptops, and orphaned test systems from cluttering the host inventory dashboard, ensuring that security operations teams maintain an accurate representation of active enterprise assets.
Question 34
What prevention policy setting prevents sensor-related files, folders, and registry objects from being renamed or deleted locally?
- Sensor Tampering Protection
- Host Modification Protection
- System Configuration Protection
- Sensor Modification Protection
Correct Answer: 1
Explanation:
Sensor Tampering Protection is a critical security setting designed to safeguard the Falcon sensor’s local installation files, program directories, driver components, and registry keys from being altered, disabled, stopped, or removed by malicious processes or unauthorized local users. By locking down these vital local binaries, the mechanism ensures that advanced threat actors cannot disable endpoint protection agents even if they manage to acquire elevated administrative privileges on the compromised host machine.
Question 35
When installing the Falcon Sensor manually on Microsoft Windows, where is the installation log data typically stored by default?
- %SYSTEMROOT%\Logs
- %SYSTEMROOT%\Temp
- %LOCALAPPDATA%\Temp
- %LOCALAPPDATA%\Logs
Correct Answer: 3
Explanation:
Manual Windows sensor installations and command-line deployments write their verbose setup logs directly into the local user’s temporary directory (%LOCALAPPDATA%\Temp). Reviewing these installation logs is essential for system administrators and deployment engineers when troubleshooting exit codes, permission barriers, missing prerequisites, or registration failures during initial agent rollouts across enterprise Windows environments.
Question 36
What are the three required parts of a Fusion SOAR workflow condition?
- Trigger, parameter, and alert
- Operator, value, and source
- Parameter, operator, and value
- Alert, action, and schedule
Correct Answer: 3
Explanation:
Fusion SOAR workflow logic evaluates filtering criteria using three mandatory components: a target parameter, a logical operator, and a specified value. Together, this triad forms the evaluation statement that dictates whether an automated workflow branch should execute based on incoming alert attributes or telemetry events. Configuring these components accurately ensures that automated remediation scripts and notification pipelines fire only under precise, intended security conditions.
Question 37
When creating new Custom Indicators of Compromise (IOCs) in IOC Management, which fields must be configured?
- Hash, Description, and Filename
- Hash, Action, and Expiry Date
- Filename, Severity, and Expiry Date
- Hash, Platform, and Action
Correct Answer: 4
Explanation:
Creating a custom Indicator of Compromise (IOC) requires defining three mandatory configuration fields: the specific artifact hash, the target operating system platform, and the enforcement action (such as block or detect). Specifying these parameters ensures that the CrowdStrike cloud correctly evaluates the custom indicator against incoming telemetry streams and applies the desired preventative or detective posture across all enrolled endpoints within the specified operating environment.
Question 38
What controls the rate at which your endpoint sensors receive automatic updates?
- Sensor update throttling
- Cloud bandwidth policies
- Host group deployment schedules
- Core kernel synchronization intervals
Correct Answer: 1
Explanation:
Sensor update throttling settings manage the distribution pace, rollout velocity, and staged delivery of automated sensor upgrades across large enterprise environments. By regulating how many endpoints download updates concurrently, throttling prevents network bandwidth saturation and avoids taxing corporate gateways during peak operational hours. Administrators can configure these velocity controls to pilot new sensor versions safely on small host groups before rolling them out globally.
Question 39
When deploying the Falcon Sensor alongside an existing legacy antivirus solution, what is the recommended configuration posture when enabling Quarantine prevention?
- Run both solutions simultaneously with maximum aggressiveness settings
- Disable or remove the other AV solution and configure NGAV Sensor Machine Learning prevention in Falcon to Moderate or higher
- Keep legacy AV active for file scanning and use Falcon strictly for network telemetry
- Enable passive monitoring mode on both tools indefinitely
Correct Answer: 2
Explanation:
Running multiple active kernel-level security products simultaneously often causes system instability, driver conflicts, performance degradation, and false positive lockouts. Industry best practice dictates uninstalling legacy third-party antivirus software entirely and fully leveraging CrowdStrike’s native prevention features by configuring Next-Gen Antivirus (NGAV) settings to Moderate or aggressive levels. This unifies endpoint protection under a single lightweight agent and maximizes behavioral detection efficacy.
Question 40
If a Falcon sensor was installed on a Virtual Machine template with the parameter NO_START=1, what behavior occurs when that template image is subsequently booted up?
- The sensor remains permanently dormant until manually started via CLI
- The sensor starts automatically at reboot and generates a new Agent ID
- The virtual machine crashes due to missing initialization flags
- The sensor uninstalls itself automatically upon detecting template cloning
Correct Answer: 2
Explanation:
Utilizing the NO_START=1 parameter during golden image template creation prevents premature sensor registration and identity generation before cloning. Once the newly provisioned virtual machine instance boots up live on the network, the sensor initializes automatically during the system reboot cycle, registers with the cloud platform, and provisions a distinct, unique Agent ID (AID) to prevent duplicate telemetry records across the infrastructure.