Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CCFA-200b CrowdStrike Falcon Certification Program Free Practice Exam Questions (2026 Updated)

Prepare effectively for your CrowdStrike CCFA-200b CrowdStrike Falcon Certification Program certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 100 questions

What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?

A.

It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

B.

It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

C.

It is designed to show malicious processes that would have been blocked in your environment based on different Machine-Learning Prevention settings

D.

It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

What prevention policy setting prevents sensor-related files, folders, and registry objects from being renamed or deleted?

A.

Host Modification Protection

B.

System Configuration Protection

C.

Sensor Tampering Protection

D.

Sensor Modification Protection

You are assigning sensor group tags during installation. What is the maximum allowed length of all tags?

A.

237 characters

B.

256 characters

C.

50 characters

D.

100 characters

In order to quarantine files on the host, what prevention policy settings must be enabled?

A.

Malware Protection and Windows Anti-Malware Execution Blocking

B.

Next-Gen Antivirus Prevention sliders and “Quarantine & Security Center Registration”

C.

Malware Protection and Custom Execution Blocking

D.

Behavior-Based Threat Prevention sliders and Advanced Remediation Actions

What best describes the relationship between Sensor Update policies and Operating Systems?

A.

A Sensor Update policy must be configured for each Operating System (Windows, Mac, Linux)

B.

Sensor Update polices are not Operating System specific; one policy can be applied to all Operating Systems

C.

Windows has its own Sensor Update polices; Mac and Linux share Sensor Update policies

D.

Windows and Mac share Sensor Update policies; Linux requires its own set of polices based on the different kernel versions

You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?

A.

Platform

B.

OS version

C.

Type

D.

OU

What type of information is provided in sensor health report?

A.

User login history

B.

Local performance metrics

C.

Current operational status

D.

Network traffic patterns

An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

A.

75 Days

B.

60 Days

C.

90 Days

D.

45 Days

During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?

A.

Put-and-Run is not enabled in the response policy

B.

Custom Scripts is not enabled in the response policy

C.

Script-Based Execution Monitoring is not enabled in the prevention policy

D.

The responder requires the RTR Administrator role

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled

B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console

C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console

D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon

What update policy does a sensor receive when it does not have a group assignment?

A.

Top precedence policy

B.

Default policy

C.

Auto N-1 policy

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

Excluding mobile devices, what kind of hosts can be contained in Falcon?

A.

Windows and MacOS hosts running the Falcon sensor

B.

Windows and Linux hosts running the Falcon sensor

C.

Windows, Linux, and container hosts running the Falcon sensor

D.

Windows, Linux, and MacOS hosts running the Falcon sensor

Where can you find hosts that have been offline for ten minutes or longer?

A.

Host Management

B.

Sensor Coverage Dashboard

C.

Host Groups

You are deploying the Falcon sensor to 500 hosts. Hosts in an Organizational Unit need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter. What is the best way to create a host group for this OU?

A.

Create a Dynamic Group targeting Windows 10 OS in the domain

B.

Create a dynamic group with an assignment rule that excludes the OU

C.

Create a dynamic group with an assignment rule that filters for the OU

From the Host management page, what is the best field to filter by for Domain Controllers to obtain sensor version information?

A.

Sensor Version

B.

Type

C.

Platform

D.

OS Version

Where would you apply a configuration to allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained?

A.

IP Allowlist Management

B.

Containment Policy

C.

Response Policies

D.

Maintenance Token

Your leadership wants controls in place for immediate action on any Overwatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?

A.

Create a Fusion SOAR workflow to contain the host and email the Overwatch team

B.

Create a Fusion SOAR workflow to create a detection for Overwatch and email the SOC team

C.

Create a Fusion SOAR workflow to trigger on an Overwatch detection and set it to block the detection

D.

Create a Fusion SOAR workflow using the Overwatch playbook to contain the host and email the SOC team

There are a significant number of false positive detections from your developers that are getting blocked and quarantined by Falcon. What Indicator of Compromise (IOC) action would be the best option?

A.

Detect Only

B.

Allow

C.

Prevent

D.

No action

In order to receive the most stable sensor updates, what level of automatic sensor updates should be applied to a host?

A.

Auto-N-2

B.

Auto-N-1

C.

Pinned sensor version

D.

Auto-Latest

Page: 1 / 2
Total 100 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved