View Full CrowdStrike CCFA-200b Exam Dumps and Practice Test Dumps.
Question 81
What is the primary purpose of the Falcon Prevent module within the CrowdStrike platform?
- To monitor cloud infrastructure configuration drift and compliance
- To provide automated next-generation antivirus (NGAV) prevention and block known/unknown malware
- To manage enterprise software licensing inventories and unmanaged assets
- To automate IT helpdesk ticket generation for hardware failures
Correct Answer: 2
Explanation:
Falcon Prevent is the core Next-Generation Antivirus (NGAV) component of the CrowdStrike platform. Its primary function is to stop malware, ransomware, and fileless attacks pre-execution and post-execution using machine learning, behavioral analysis, custom indicators of attack (IOAs), and signatureless detection techniques. It ensures endpoints are actively protected against sophisticated threats without relying on traditional, resource-heavy signature updates.
Question 82
How does the Falcon sensor handle high CPU or memory utilization spikes on an endpoint during intensive security scanning?
- The sensor crashes and generates a kernel dump file
- The sensor is engineered with resource throttling mechanisms to limit CPU and memory impact
- The operating system automatically uninstalls the sensor
- The endpoint is forcibly isolated from the local network
Correct Answer: 2
Explanation:
The Falcon sensor is designed to operate with a lightweight footprint to avoid impacting end-user productivity. It utilizes built-in resource throttling and efficient kernel-mode architecture to monitor system activity continuously. By regulating resource consumption, the sensor minimizes CPU and memory overhead, ensuring that normal operating system functions and user applications run smoothly without noticeable performance degradation.
Question 83
What is the recommended method for an administrator to investigate a suspicious PowerShell command executed on an endpoint?
- Review the Process Timeline and command-line arguments in Falcon Insight / Event Search
- Check the local Windows recycle bin on the physical machine
- Reboot the computer into safe mode and inspect user profile folders
- Run a manual disk defragmentation utility
Correct Answer: 1
Explanation:
When investigating suspicious command-line activity such as encoded PowerShell scripts, analysts use Falcon Insight’s Process Timeline and Event Search capabilities. This interface provides detailed visibility into parent-child process chains, exact command-line arguments, executing user accounts, and spawned child processes, allowing responders to evaluate malicious intent quickly without needing direct physical access to the machine.
Question 84
Which CrowdStrike Falcon feature enables administrators to monitor file modifications across sensitive directories for compliance auditing?
- Falcon FileVantage
- Falcon Discover
- Falcon Spotlight
- Falcon Horizon
Correct Answer: 1
Explanation:
Falcon FileVantage delivers robust file integrity monitoring (FIM) capabilities. Administrators use FileVantage to track, audit, and log real-time modifications, creations, and deletions of critical system files, configuration settings, and registry paths. This ensures organizations can meet strict regulatory compliance mandates while rapidly identifying unauthorized alterations or persistence mechanisms.
Question 85
What is the function of the NO_START=1 parameter when installing the Falcon sensor?
- It uninstalls the sensor immediately after installation
- It prevents the sensor from starting and registering automatically until the host is rebooted or manually initiated
- It disables all firewall rules on the local machine
- It forces the sensor into passive monitoring mode permanently
Correct Answer: 2
Explanation:
The NO_START=1 parameter is commonly utilized during golden image or virtual machine template creation. It suppresses immediate sensor startup and cloud registration upon initial installation. This prevents multiple cloned virtual machines from registering under a single duplicate identity token, ensuring that each provisioned instance initializes and acquires its unique Agent ID (AID) cleanly upon its first live boot.
Question 86
Which console page provides an overview of overall sensor deployment health, operating system distribution, and offline host counts?
- Sensor Downloads Page
- Host Management Dashboard
- API Clients and Keys Menu
- Fusion Workflow Builder
Correct Answer: 2
Explanation:
The Host Management dashboard serves as the central operational view for monitoring enterprise endpoint coverage. It displays real-time statistics regarding active versus offline hosts, operating system distributions, sensor version breakdowns, containment statuses, and overall agent health. This helps administrators verify deployment completeness and identify unmanaged or disconnected systems.
Question 87
What role does threat intelligence play within the CrowdStrike Threat Graph architecture?
- It provides local weather forecasts for regional offices
- It correlates global telemetry in real time to instantly distribute behavioral indicators across all connected customers
- It manages user password expiration policies in Active Directory
- It compresses system log files to conserve cloud storage space
Correct Answer: 2
Explanation:
The cloud-native Threat Graph ingests trillions of security events daily from global endpoints. By combining this telemetry with advanced threat intelligence, the platform performs real-time event correlation. When a new adversary tactic or attack vector is identified in one environment, Threat Graph instantly updates defensive models and protects all CrowdStrike customers worldwide against the emerging threat.
Question 88
What is the primary purpose of creating a Custom Response Policy in Falcon?
- To define which users can log into the Falcon console GUI
- To control and configure Real Time Response (RTR) permissions and feature availability for specific host groups
- To schedule automatic operating system patch deployments
- To establish global firewall rules for corporate routers
Correct Answer: 2
Explanation:
Custom Response Policies allow administrators to fine-tune Real Time Response (RTR) capabilities across different segments of the organization. For example, security teams can enable full active response capabilities for standard workstations while restricting or disabling RTR functionality entirely on sensitive server environments, aligning technical controls with internal governance and compliance policies.
Question 89
How do IOA (Indicator of Attack) rules differ primarily from traditional file hash blacklists?
- IOA rules look for static MD5 strings, whereas hash lists analyze network traffic
- IOA rules evaluate dynamic adversary behaviors and execution patterns regardless of the specific file name or hash used
- IOA rules only function when the endpoint is completely disconnected from the internet
- IOA rules are restricted exclusively to mobile operating systems
Correct Answer: 2
Explanation:
Traditional hash blacklists can easily be evaded by attackers altering a single byte of a file to generate a new hash. In contrast, IOA (Indicator of Attack) rules focus on adversary intent and behavioral patterns—such as suspicious process injections, credential dumping techniques, or anomalous command-line executions—allowing the platform to detect novel and polymorphic attacks even if the file hash has never been seen before.
Question 90
What is the recommended administrative action if a critical production server is actively exhibiting signs of a severe cyber intrusion?
- Immediately place the host into Network Containment via the Falcon console
- Uninstall the sensor to clear local memory buffers
- Send an email notification to the end-user and wait for them to reboot
- Delete all prevention policies associated with the host group
Correct Answer: 1
Explanation:
When a compromised host poses an active threat to the enterprise, placing the machine into Network Containment is the most effective immediate containment step. Network Containment isolates the device at the driver level to halt lateral movement, worm propagation, and data exfiltration while maintaining an encrypted communication pipeline so incident responders can investigate and remediate via Real Time Response.
Question 91
Which feature enables automated response actions, such as isolating hosts or notifying security teams via webhooks, when a detection occurs?
- Falcon Fusion SOAR
- Falcon Spotlight Vulnerability Management
- Falcon Discover IT Hygiene
- Falcon FileVantage FIM
Correct Answer: 1
Explanation:
Falcon Fusion is CrowdStrike’s integrated Security Orchestration, Automation, and Response (SOAR) engine. It empowers administrators to build automated playbooks utilizing customizable triggers, conditions, and actions. Fusion streamlines security operations by automating repetitive tasks, such as triggering host containment, dispatching alert notifications to collaboration tools, or creating IT service management tickets upon detection.
Question 92
Where can an administrator locate audit logs showing who modified a prevention policy or created an exclusion in the Falcon console?
- Falcon UI Audit Trail
- Sensor Download Logs
- Local Windows Event Viewer
- Host Management Trash Bin
Correct Answer: 1
Explanation:
The Falcon UI Audit Trail maintains a comprehensive, chronological record of all administrative actions performed within the console. It tracks user sign-ins, policy updates, exclusion creations, containment commands, and administrative role modifications. This audit trail is vital for maintaining organizational accountability, supporting compliance requirements, and reviewing changes made by platform users.
Question 93
What is the primary benefit of deploying Falcon Spotlight for vulnerability management?
- It eliminates the need for network-based vulnerability scanners by leveraging the lightweight Falcon sensor to assess vulnerabilities in real time
- It automatically updates local printer drivers across all workstations
- It blocks unauthorized USB flash drives from connecting to endpoints
- It manages corporate firewall inbound ports
Correct Answer: 1
Explanation:
Falcon Spotlight revolutionizes vulnerability management by eliminating resource-intensive, intrusive network scanning tools. Because the lightweight Falcon sensor already has deep visibility into operating systems and installed software, Spotlight continuously assesses endpoints against known Common Vulnerabilities and Exposures (CVEs), providing security teams with prioritized, real-time risk scoring and actionable remediation data.
Question 94
Which CrowdStrike module provides continuous visibility into cloud infrastructure posture across AWS, Azure, and Google Cloud?
- Falcon Horizon (CSPM)
- Falcon Prevent (NGAV)
- Falcon Insight (EDR)
- Falcon Discover (IT Hygiene)
Correct Answer: 1
Explanation:
Falcon Horizon provides Cloud Security Posture Management (CSPM) across multi-cloud environments. It continuously scans cloud resource configurations, identifies security misconfigurations, checks compliance adherence, and detects infrastructure vulnerabilities. This ensures security operations teams maintain complete visibility and robust security posture management across complex cloud-native architectures.
Question 95
What administrative step is required to ensure that a newly modified Prevention Policy only applies to developer workstations?
- Assign the policy specifically to the Host Group containing the developer workstations
- Copy the policy XML file to every developer’s desktop manually
- Enter the individual IP addresses of the developer machines into the global firewall settings
- Run a local command-line script on each developer laptop
Correct Answer: 1
Explanation:
Policy scoping in the CrowdStrike Falcon console is managed through Host Groups. To target a specific configuration—such as adjusted machine learning or exclusion rules—to developer workstations, the administrator must assign that custom Prevention Policy directly to the designated Host Group representing those endpoints, ensuring precise and controlled policy enforcement.
Question 96
What does an active “Containment” status indicate regarding an endpoint’s network connectivity?
- The host has been completely disconnected from the internet and local network, except for secure communication with the CrowdStrike cloud
- The host has had all its local user accounts deleted by the sensor
- The host is running in passive monitoring mode without kernel telemetry
- The host’s hard drive has been remotely wiped of all data
Correct Answer: 1
Explanation:
When Network Containment is enforced, the Falcon sensor’s driver isolates the machine from all internal network communication and external internet access, effectively blocking lateral movement and data theft. However, a secure, dedicated connection to the CrowdStrike cloud is maintained so analysts retain remote access via Real Time Response to investigate, retrieve forensic evidence, and lift containment when remediation is complete.
Question 97
Which role should be assigned to an analyst who needs to inspect files via Real Time Response but must not have permission to download or extract those files off the endpoint?
- Real Time Responder – Read Only Analyst
- Falcon Administrator
- Remediation Manager
- Active Responder
Correct Answer: 1
Explanation:
The “Real Time Responder – Read Only Analyst” role permits security personnel to connect to endpoints via RTR to inspect directories, view file structures, and execute read-only commands for triage purposes. Crucially, it blocks file extraction and administrative remediation capabilities, preventing unauthorized data exfiltration while allowing junior analysts or auditors to perform necessary investigations safely.
Question 98
How does Falcon Discover assist IT and security teams with asset management?
- By automatically detecting unmanaged endpoints, shadow IT devices, and IoT hardware connected to the corporate network
- By defragmenting hard drive storage sectors during off-hours
- By scheduling automatic operating system reboots
- By generating local antivirus signature files
Correct Answer: 1
Explanation:
Falcon Discover enhances IT hygiene by identifying unmanaged assets, rogue devices, shadow IT, and unsupported IoT hardware operating across the corporate network. By leveraging network traffic telemetry and peer observation from protected systems, Discover highlights coverage gaps, helps security teams enforce agent deployment, and ensures complete enterprise visibility.
Question 99
What is the correct procedure when an authorized administrative tool is incorrectly flagged and blocked by a behavioral IOA rule?
- Permanently delete the Falcon sensor from all machines
- Create a targeted IOA Exclusion specifying the exact process path, command-line parameters, or parent process
- Disable all security policies across the entire organization indefinitely
- Ignore the security alerts and instruct users to bypass the error manually each time
Correct Answer: 2
Explanation:
When an administrative tool or custom script triggers a false positive behavioral alert, security best practices require analyzing the detection details, confirming the activity is legitimate, and creating a precise IOA Exclusion. By specifying exact parameters such as file paths, command-line wildcards, or parent processes, administrators prevent future false positives without compromising overall endpoint protection or disabling core security rules.
Question 100
What is the primary function of the CrowdStrike Falcon Sensor Update Policy?
- To schedule Windows operating system security patches
- To control sensor software versions, manage update velocity, and dictate phased deployment rings for endpoints
- To update third-party browser plugins automatically
- To configure corporate Wi-Fi network routing tables
Correct Answer: 2
Explanation:
Sensor Update Policies give administrators central control over sensor version management and deployment pacing. Teams can pin specific host groups to fixed sensor builds, test new releases in staging environments before global rollouts, or regulate update throttling to prevent network bandwidth saturation during peak operational hours across the enterprise.