Month End Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CCFA-200 Exam Dumps - CrowdStrike Falcon Certification Program Questions and Answers

Question # 14

Which command would tell you if a Falcon Sensor was running on a Windows host?

Options:

A.

cswindiag.exe -status

B.

netstat.exe -f

C.

sc.exe query csagent

D.

sc.exe query falcon

Buy Now
Question # 15

An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

Options:

A.

45 Days

B.

60 Days

C.

75 Days

D.

90 Days

Buy Now
Question # 16

What may prevent a user from logging into Falcon via single sign-on (SSO)?

Options:

A.

The SSO username doesn't match their email address in Falcon

B.

The maintenance token has expired

C.

Falcon is in reduced functionality mode

D.

The user never configured their security questions

Buy Now
Question # 17

What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?

Options:

A.

Microsoft updates altering the kernel

B.

The host lost internet connectivity

C.

A misconfiguration in your prevention policy for the host

D.

A Sensor Update Policy was misconfigured

Buy Now
Question # 18

You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?

Options:

A.

Go to Host Management in the Host page. Select the host and use the Export Detections button

B.

Utilize the Detection Resolution Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detection Resolution History" section

C.

In the Investigate module, access the Detection Activity page. Use the filters to focus on the appropriate hostname and time, then export the results

D.

Utilize the Detection Activity Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detections by Host" section

Buy Now
Question # 19

What can the Quarantine Manager role do?

Options:

A.

Manage and change prevention settings

B.

Manage quarantined files to release and download

C.

Manage detection settings

D.

Manage roles and users

Buy Now
Question # 20

What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?

Options:

A.

Endpoint ID (EID)

B.

Agent ID (AID)

C.

Security ID (SID)

D.

Computer ID (CID)

Buy Now
Question # 21

What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?

Options:

A.

For - While statement(s)

B.

Trigger, condition(s) and action(s)

C.

Event trigger(s)

D.

Predefined workflow template(s)

Buy Now
Question # 22

What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?

Options:

A.

Falcon console updates are pending

B.

Falcon sensors installing an update

C.

Notifications have been disabled on that host sensor

D.

Microsoft updates

Buy Now
Question # 23

When editing an existing IOA exclusion, what can NOT be edited?

Options:

A.

The IOA name

B.

All parts of the exclusion can be changed

C.

The exclusion name

D.

The hosts groups

Buy Now
Exam Code: CCFA-200
Exam Name: CrowdStrike Certified Falcon Administrator
Last Update: Jan 31, 2025
Questions: 153
CCFA-200 pdf

CCFA-200 PDF

$25.5  $84.99
CCFA-200 Engine

CCFA-200 Testing Engine

$28.5  $94.99
CCFA-200 PDF + Engine

CCFA-200 PDF + Testing Engine

$40.5  $134.99