
CrowdStrike CCFA-200 Real Exam Questions Guaranteed Updated Dump from ExamCost
Verified Pass CCFA-200 Exam in First Attempt Guaranteed
NEW QUESTION # 86
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?
- A. TCP port 443 (HTTPS)
- B. TCP port 80 (HTTP)
- C. TCP UDP port 53 (DNS)
- D. TCP port 22 (SSH)
Answer: A
Explanation:
Explanation
The sensor uses TCP port 443 (HTTPS) to communicate with the CrowdStrike Cloud. This port and protocol are used to securely send and receive data between the sensor and the cloud, such as detections, policies, updates, commands, etc. The other options are either incorrect or not used by the sensor.
Reference: CrowdStrike Falcon User Guide, page 28.
NEW QUESTION # 87
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
- A. Domain
- B. Hostname
- C. Username
- D. Model
Answer: B
Explanation:
Explanation
When performing targeted filtering for a host on the Host Management Page, the filter bar attribute that is not case-sensitive is Hostname. The Hostname attribute allows you to filter hosts by their computer name or DNS name. The Hostname filter is not case-sensitive, meaning that it will match hosts regardless of the capitalization of their names. For example, filtering by hostname=DESKTOP-1234 will match hosts with names such as DESKTOP-1234, desktop-1234, or Desktop-12342.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 88
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
- A. Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"
- B. Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.
- C. Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"
- D. Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running
Answer: B
NEW QUESTION # 89
Which of the following scenarios best describes when you would add IP addresses to the containment policy?
- A. You want to automate the Network Containment process based on the IP address of a host
- B. Your organization has additional IP addresses that need to be able to access the Falcon console
- C. Your organization has resources that need to be accessible when hosts are network contained
- D. A new group of analysts need to be able to place hosts under Network Containment
Answer: C
Explanation:
Explanation
The scenario that best describes when you would add IP addresses to the containment policy is that your organization has resources that need to be accessible when hosts are network contained. As explained in the previous question, adding IP addresses to the containment policy allows you to create an allowlist of trusted IP addresses that can communicate with your contained hosts. This can be useful when you need to isolate a host from the network due to a potential compromise or investigation, but still want to allow it to access certain resources or services that are essential for your organization's operations or security2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 90
How are user permissions set in Falcon?
- A. Permissions are token-based. Users request access to a defined set of permissions and an administrator adds their token to the set of permissions
- B. An administrator selects individual granular permissions from the Falcon Permissions List during user creation
- C. Pre-defined permissions are assigned to sets called roles. Users can be assigned multiple roles based on job function and they assume a cumulative set of permissions based on those assignments
- D. Permissions are assigned to a User Group and then users are assigned to that group, thereby inheriting those permissions
Answer: C
NEW QUESTION # 91
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
- A. Detection slider: Cautious
Prevention slider: Cautious - B. Detection slider: Moderate
Prevention slider: Disabled - C. Detection slider: Extra Aggressive
Prevention slider: Cautious - D. Detection slider: Disabled
Prevention slider: Disabled
Answer: A
NEW QUESTION # 92
Which role will allow someone to manage quarantine files?
- A. Falcon Security Lead
- B. Detections Exceptions Manager
- C. Falcon Analyst - Read Only
- D. Endpoint Manager
Answer: A
Explanation:
Explanation
The role that will allow someone to manage quarantine files is Falcon Security Lead. This role allows users to view and manage quarantined files, as well as release them from quarantine or download them for further analysis. The other roles do not have this capability. Reference: CrowdStrike Falcon User Guide, page 19.
NEW QUESTION # 93
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
- A. Under Dashboards and reports, choose the Sensor Report. Set the "Last Seen" dropdown to 30 days and reference the Inactive Sensors widget
- B. Under Host setup and management, choose the Host Management page. Set the group filter to "Inactive Sensors"
- C. Under Host setup and management, choose the Disabled Sensors Report. Change the time range to 30 days
- D. Under Host setup and management > Managed endpoints > Inactive Sensors. Change the time range to 30 days
Answer: D
NEW QUESTION # 94
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
- A. Detection slider: Cautious
Prevention slider: Cautious - B. Detection slider: Moderate
Prevention slider: Disabled - C. Detection slider: Extra Aggressive
Prevention slider: Cautious - D. Detection slider: Disabled
Prevention slider: Disabled
Answer: A
Explanation:
Explanation
The best settings to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase are Cautious for both Detection and Prevention sliders. This setting will enable the sensor to detect and prevent only high-confidence malicious events, while allowing low-confidence events to run without interference. This setting will also generate less noise and false positives than higher settings, such as Moderate or Extra Aggressive1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 95
You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?
- A. System monitoring will be unavailable
- B. Some detection patterns and preventions will not be triggered
- C. Prevention patterns will not be triggered
- D. Event reporting will be unavailable
Answer: B
Explanation:
Explanation
The option that is true when a Windows host is in Reduced Functionality Mode (RFM) is that some detection patterns and preventions will not be triggered. RFM is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. When a Windows sensor is in RFM, it will only provide basic prevention capabilities, such as blocking known malware hashes and preventing script execution from the %TEMP% directory. The sensor will not send any telemetry or detection events to the Falcon platform, and will not receive any policy or update changes from the Falcon cloud. This means that some detection patterns and preventions that rely on telemetry, machine learning, or cloud analysis will not be triggered.
References: : [Falcon Administrator Learning Path | Infographic | CrowdStrike]
NEW QUESTION # 96
Custom IOA rules are defined using which syntax?
- A. Regex
- B. Yara
- C. PowerShell
- D. Glob
Answer: C
NEW QUESTION # 97
Which of the following pages provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System?
- A. Hosts Overview
- B. Support and resources
- C. Sensor Health
- D. Activity Overview
Answer: C
Explanation:
Explanation
The page that provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System is Sensor Health. The Sensor Health page allows you to view and monitor the health and status of all sensors in your environment. You can use this page to identify any sensors that have issues or errors, such as RFM, which is a mode that limits the sensor's functionality due to license expiration, network connectivity loss, or certificate validation failure. You can filter the sensors by operating system, sensor version, last seen date, health events, detections, and preventions3.
References: 3: How to Become a CrowdStrike Certified Falcon Administrator
NEW QUESTION # 98
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
- A. Machine Learning Prevention Monitoring
- B. Machine Learning Debug
- C. Sensor Report
- D. Falcon UI Audit Trail
Answer: A
Explanation:
Explanation
The Machine Learning Prevention Monitoring report in the Prevention Policy Management option allows you to monitor the impact of machine learning (ML) prevention settings on your environment. You can view the number of ML detections and preventions by severity, policy, and host group. You can also drill down into specific events and hosts to see more details. This report can help you determine the appropriate ML levels to set in a prevention policy based on your risk tolerance and security posture1.
References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike
NEW QUESTION # 99
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
- A. Computer ID (CID)
- B. Endpoint ID (EID)
- C. Security ID (SID)
- D. Agent ID (AID)
Answer: D
Explanation:
Explanation
The name for the unique host identifier in Falcon assigned to each sensor during sensor installation is Agent ID (AID). The AID is a 32-character hexadecimal string that uniquely identifies each sensor and host in the Falcon platform. The other options are either incorrect or not related to the sensor identifier.
Reference: CrowdStrike Falcon User Guide, page 28.
NEW QUESTION # 100
How can a Falcon Administrator configure a pop-up message to be displayed on a host when the Falcon sensor blocks, kills or quarantines an activity?
- A. By selecting "Enable pop-up messages" from the User configuration page
- B. By enabling "Upload quarantined files" in the General Settings configuration page
- C. By turning on the "Notify End Users" setting at the top of the Prevention policy details configuration page
- D. By ensuring each user has set the "pop-ups allowed" in their User Profile configuration page
Answer: C
NEW QUESTION # 101
How long are detection events kept in Falcon?
- A. Detections events are kept for your subscribed data retention period
- B. Detection events are kept for 30 days
- C. Detection events are kept for 7 days
- D. Detection events are kept for 90 days
Answer: D
Explanation:
Explanation
" Data is only available in the Falcon UI for investigations, etc. through the company's data retention time frame; detection information is kept for 90 days regardless; UI audits are available for 1 year
NEW QUESTION # 102
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?
- A. In the Investigate module, access the Detection Activity page. Use the filters to focus on the appropriate hostname and time, then export the results
- B. Utilize the Detection Resolution Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detection Resolution History" section
- C. Utilize the Detection Activity Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detections by Host" section
- D. Go to Host Management in the Host page. Select the host and use the Export Detections button
Answer: A
Explanation:
Explanation
The best way to export a list of all deletions for a specific Host Name in the last 24 hours is to go to the Investigate module, access the Detection Activity page, use the filters to focus on the appropriate hostname and time, then export the results. This will allow you to download a CSV file that contains information about all the detections that were deleted for that host in that time period. The other options are either incorrect or not related to exporting deletions. Reference: CrowdStrike Falcon User Guide, page 49.
NEW QUESTION # 103
Which of the following best describes the Default Sensor Update policy?
- A. The Default Sensor Update policy does not have the "Uninstall and maintenance protection" feature
- B. The Default Sensor Update policy is disabled by default
- C. The Default Sensor Update policy is a "catch-all" policy
- D. The Default Sensor Update policy is only used for testing sensor updates
Answer: C
Explanation:
Explanation
The Default Sensor Update policy is a "catch-all" policy. This means that any host that is not assigned to a specific sensor update policy will inherit the settings from the Default Sensor Update policy. The Default Sensor Update policy is enabled by default and has the "Uninstall and maintenance protection" feature turned on. You can modify the settings of the Default Sensor Update policy, but you cannot delete or disable it2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 104
Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?
- A. Falcon Investigator
- B. Real Time Responder
- C. Remediation Manager
- D. Endpoint Manager
Answer: A
NEW QUESTION # 105
On which page of the Falcon console can one locate the Customer ID (CID)?
- A. Sensor Dashboard
- B. API Clients and Keys
- C. Sensor Downloads
- D. Hosts Management
Answer: B
Explanation:
Explanation
The page of the Falcon console where one can locate the Customer ID (CID) is API Clients and Keys. The API Clients and Keys page allows you to create and manage API clients and keys for accessing the Falcon platform programmatically. The Customer ID (CID) is a unique identifier for your organization that is required for authenticating your API requests. You can find your CID at the top of the API Clients and Keys page2.
References: 2: Cybersecurity Resources | CrowdStrike
NEW QUESTION # 106
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A. It is an auditing requirement
- B. There may be special considerations for each OS
- C. To assist with testing and tracking sensor rollouts
- D. The network protocols are different for each host OS
Answer: A
NEW QUESTION # 107
What command should be run to verify if a Windows sensor is running?
- A. sc query csagent
- B. netstat -f
- C. ps -ef | grep falcon
- D. regedit myfile.reg
Answer: A
Explanation:
Explanation
The command that should be run to verify if a Windows sensor is running is sc query csagent. This command will display the status and information of the csagent service, which is the Falcon sensor service. The other commands are either incorrect or not applicable to Windows sensors. Reference: [CrowdStrike Falcon User Guide], page 29.
NEW QUESTION # 108
......
Download Real CrowdStrike CCFA-200 Exam Dumps Test Engine Exam Questions: https://www.examcost.com/CCFA-200-practice-exam.html
Free CCFA-200 Sample Questions and 100% Cover Real Exam Questions: https://drive.google.com/open?id=1LsstU_Yk0Ih0JH-n910rhi6XXOy7LNuq

