Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Mar 23, 2025

CrowdStrike CrowdStrike Certifications CCFA-200 Questions & Answers

  • Question 31:

    Which of the following is NOT an available filter on the Hosts Management page?

    A. Hostname

    B. Username

    C. Group

    D. OS Version

  • Question 32:

    Which option allows you to exclude behavioral detections from the detections page?

    A. Machine Learning Exclusion

    B. IOA Exclusion

    C. IOC Exclusion

    D. Sensor Visibility Exclusion

  • Question 33:

    The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.

    A. the account type for the user (e.g. Domain Administrator, Local User)

    B. all hosts the user logged into

    C. the logon type (e.g. interactive, service)

    D. the last time the user's password was set

  • Question 34:

    Where in the Falcon console can information about supported operating system versions be found?

    A. Configuration module

    B. Intelligence module

    C. Support module

    D. Discover module

  • Question 35:

    You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?

    A. Script-based Execution Monitoring

    B. Interpreter-Only

    C. Additional User Mode Data

    D. Engine (Full Visibility)

  • Question 36:

    Which of the following can a Falcon Administrator edit in an existing user's profile?

    A. First or Last name

    B. Phone number

    C. Email address

    D. Working groups

  • Question 37:

    With Custom Alerts, it is possible to __________.

    A. schedule the alert to run at any interval

    B. receive an alert in an email

    C. configure prevention actions for alerting

    D. be alerted to activity in real-time

  • Question 38:

    Custom IOA rules are defined using which syntax?

    A. Glob

    B. PowerShell

    C. Yara

    D. Regex

  • Question 39:

    When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?

    A. Maintenance token

    B. Customer ID (CID)

    C. Bulk update key

    D. Agent ID (AID)

  • Question 40:

    Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?

    A. Workflow Execution log

    B. Falcon Ul Audit Trail

    C. Workflow Audit log

    D. Custom Alert History

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.