Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CCFA-200b Premium Access

View all detail and faqs for the CCFA-200b exam


443 Students Passed

92% Average Score

91% Same Questions
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?

Options:

A.

Create an exclusion for the felix.dll file

B.

Create an IOA exclusion for C:\Users\Bob\DevCode\felix.dll

C.

Create a separate Host Group for development machines and apply a less restrictive policy

D.

Create a Custom IOC and set it to Allow for C:\Users\Bob\DevCode\felix.dll

Questions # 2:

Which Windows prevention policy setting monitors contents of shells for execution of malicious content?

Options:

A.

Script-based execution visibility

B.

Suspicious Scripts and Commands

C.

Enhanced exploitation visibility

D.

Additional user mode data visibility

Questions # 3:

Which ML exclusion pattern would be the most accurate for all .exe binaries in “C:\Program Files\Software\”, including any subfolders of Software?

Options:

A.

Program Files\Software* .exe

B.

Program Files\Software*.exe

C.

Program Files\Software* *.exe

D.

***.exe

Questions # 4:

An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

Options:

A.

75 Days

B.

60 Days

C.

90 Days

D.

45 Days

Questions # 5:

What is true about the Default Sensor Policy?

Options:

A.

It tests the sensor configuration settings before deployment

B.

It is applied automatically if no other Sensor Policies are applied

C.

It can be used to reset all sensor settings to Default

D.

It is a mechanism to deploy the oldest supported version of the Falcon Sensor

Questions # 6:

You have created a new static host group to test a newly created sensor update policy, and need to add 500 servers into the group. You want to upload a list of hosts to Falcon for automatic addition into the group. What file format must the list be for this to be successfully accomplished?

Options:

A.

XLSX

B.

PDF

C.

TXT

D.

JSON

Questions # 7:

When creating your own Fusion SOAR workflow based on an Event trigger, which additional option will refine the trigger?

Options:

A.

Condition

B.

Parameter

C.

Filter

D.

Trigger Details

Questions # 8:

What default user role can manage API credentials?

Options:

A.

Falcon Security Lead

B.

Falcon Administrator

C.

Falcon API Manager

D.

Endpoint Manager

Questions # 9:

What policy setting should be selected for a new host when it has an existing antivirus?

Options:

A.

Extra Aggressive Level ML

B.

Aggressive Level ML

C.

Moderate Level ML

D.

Cautious Level ML

Questions # 10:

What is the primary purpose of custom IOA rules?

Options:

A.

Block known malware

B.

Identify malicious behavior

C.

Manage system updates

D.

Configure network settings

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.