Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Mar 23, 2025

CrowdStrike CrowdStrike Certifications CCFA-200 Questions & Answers

  • Question 131:

    What must an admin do to reset a user's password?

    A. From User Management, open the account details for the affected user and select "Generate New Password"

    B. From User Management, select "Reset Password" from the three dot menu for the affected user account

    C. From User Management, select "Update Account" and manually create a new password for the affected user account

    D. From User Management, the administrator must rebuild the account as the certificate for user specific private/public key generation is no longer valid

  • Question 132:

    How many "Auto" sensor version update options are available for Windows Sensor Update Policies?

    A. 1

    B. 2

    C. 0

    D. 3

  • Question 133:

    What is the primary purpose of using glob syntax in an exclusion?

    A. To specify a Domain be excluded from detections

    B. To specify exclusion patterns to easily exclude files and folders and extensions from detections

    C. To specify exclusion patterns to easily add files and folders and extensions to be prevented

    D. To specify a network share be excluded from detections

  • Question 134:

    You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?

    A. A Sensor Update Policy was misconfigured

    B. A host was offline for more than 24 hours

    C. A patch was pushed overnight to all Windows systems

    D. A host was placed in network containment from a detection

  • Question 135:

    Why would you assign hosts to a static group instead of a dynamic group?

    A. You do not want the group membership to change automatically

    B. You are managing more than 1000 hosts

    C. You need hosts to be automatically assigned to a group

    D. You want the group to contain hosts from multiple operating systems

  • Question 136:

    You want to create a detection-only policy. How do you set this up in your policy's settings?

    A. Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.

    B. Select the "Detect-Only" template. Disable hash blocking and exclusions.

    C. You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.

    D. Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.

  • Question 137:

    How many days will an inactive host remain visible within the Host Management or Trash pages?

    A. 45 days

    B. 15 days

    C. 90 days

    D. 120 days

  • Question 138:

    What is the purpose of using groups with Sensor Update policies in CrowdStrike Falcon?

    A. To group hosts with others in the same business unit

    B. To group hosts according to the order in which Falcon was installed, so that updates are installed in the same order every time

    C. To prioritize the order in which Falcon updates are installed, so that updates are not installed all at once leading to network congestion

    D. To allow the controlled assignment of sensor versions onto specific hosts

  • Question 139:

    What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?

    A. Endpoint ID (EID)

    B. Agent ID (AID)

    C. Security ID (SID)

    D. Computer ID (CID)

  • Question 140:

    Which of the following is TRUE regarding disabling detections for a host?

    A. After disabling detections, the host will operate in Reduced Functionality Mode (RFM) until detections are enabled

    B. After disabling detections, the data for all existing detections prior to disabling detections is removed from the Event Search

    C. The DetectionSummaryEvent continues being sent to the Streaming API for that host

    D. The detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.