Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Mar 31, 2025

CrowdStrike CrowdStrike Certifications CCFA-200 Questions & Answers

  • Question 81:

    Which report lists counts of sensors in Reduced Functionality Mode (RFM) for all operating system types, and tracks how long a sensor version will be supported?

    A. Reduce Functionality Audit Report

    B. Sensor Health Report

    C. Sensor Coverage Lookup

    D. Inactive Sensor Report

  • Question 82:

    Which statement describes what is recommended for the Default Sensor Update policy?

    A. The Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible

    B. The Default Sensor Update should be configured to always automatically upgrade to the latest sensor version

    C. Since the Default Sensor Update policy is pre-configured with recommend settings out of the box, configuration of the Default Sensor Update policy is not required

    D. No configuration is required. Once a Custom Sensor Update policy is created the Default Sensor Update policy is disabled

  • Question 83:

    What three things does a workflow condition consist of?

    A. A parameter, an operator, and a value

    B. A beginning, a middle, and an end

    C. Triggers, actions, and alerts

    D. Notifications, alerts, and API's

  • Question 84:

    Why is the ability to disable detections helpful?

    A. It gives users the ability to set up hosts to test detections and later remove them from the console

    B. It gives users the ability to uninstall the sensor from a host

    C. It gives users the ability to allowlist a false positive detection

    D. It gives users the ability to remove all data from hosts that have been uninstalled

  • Question 85:

    You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?

    A. Add an allowlist entry for the individual server's MAC address

    B. Add an allowlist entry containing the host group that the server belongs to

    C. Add an allowlist entry for the individual server's IP address

    D. Add an allowlist entry containing CIDR notation for the /24 network the server belongs to

  • Question 86:

    What impact does disabling detections on a host have on an API?

    A. Endpoints with detections disabled will not alert on anything until detections are enabled again

    B. Endpoints cannot have their detections disabled individually

    C. DetectionSummaryEvent stops sending to the Streaming API for that host

    D. Endpoints with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed

  • Question 87:

    When editing an existing IOA exclusion, what can NOT be edited?

    A. The IOA name

    B. All parts of the exclusion can be changed

    C. The exclusion name

    D. The hosts groups

  • Question 88:

    Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?

    A. To bundle the Sensor and Prevention policies together into a deployment package

    B. Sensor Update policies are OS dependent

    C. To assist with auditing and change management

    D. This is false. One policy can be applied to all Operating Systems

  • Question 89:

    You have been asked to troubleshoot why Script Based Execution Monitoring (SBEM) is not enabled on a Falcon host. Which report can be used to determine if this is an issue with an old prevention policy?

    A. Host Update Status Report

    B. Custom Alerting Audit Trail

    C. Prevention Policy Debug

    D. SBEM Debug Report

  • Question 90:

    You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?

    A. *nix

    B. Windows

    C. Both Windows and *nix

    D. Only Mac

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.