Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CCFA-200b Premium Access

View all detail and faqs for the CCFA-200b exam


443 Students Passed

92% Average Score

91% Same Questions
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

In order to prevent duplicate Agent IDs, what install parameter should be used on VMs to be used as persistent clones?

Options:

A.

ProvNoWait=1

B.

VDI=true

C.

NO_START=1

D.

VM=True

Questions # 12:

To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group. What is required to safely and successfully test your new sensor update policy on only your test Windows servers?

Options:

A.

The new policy must be enabled and assigned a precedence that is lower when compared to the policy assigned to all Windows servers

B.

The new policy must be enabled and assigned a precedence that is higher when compared to the policy assigned to all Windows servers

C.

The new Falcon sensor version should be manually installed by you on every test Windows server before ever enabling and assigning the new policy

D.

The new Falcon sensor version should be manually uninstalled by you on every test Windows server before ever enabling and assigning the new policy

Questions # 13:

You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?

Options:

A.

Create a static group with the assignment rule criteria set to OS Type Workstation

B.

Create a dynamic group with the assignment rule criteria set to OS Type Workstation

C.

Create a static group with the assignment rule criteria for OS Version set to Windows 10

D.

Create a dynamic group with the assignment rule criteria for OS Version set to Windows 10

Questions # 14:

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

Options:

A.

Delete the detections in the console and contain the server undergoing the test

B.

Temporarily disable detections for the server in Host Management and reenable after the test is done

C.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

D.

Permanently disable detections for the server in Host Management

Questions # 15:

How are custom roles assigned to users to perform a specific action on a module?

Options:

A.

Users get all permissions by default

B.

Permissions are enabled in roles, and these roles are assigned to users

C.

By adding each module to a role

D.

Permissions are assigned to users directly in user management

Questions # 16:

When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?

Options:

A.

Customer ID and Integration ID

B.

Client ID and Secret

C.

Customer ID and Secret

D.

Client ID and OAuth2 ID

Questions # 17:

What log would you use to investigate unusual activity invoked with a script interfacing with the Falcon platform?

Options:

A.

Falcon UI audit

B.

RTR session audit

C.

Prevention policy debug

D.

API audit

Questions # 18:

How can you search for multiple hostnames at the same time via Host Management?

Options:

A.

Enter the multiple hostnames in the Hostname filter separating each by a comma

B.

Add the Hostname filter multiple times and enter separate hostnames into each filter

C.

Enter the multiple hostnames in the Hostname filter separating each by a decimal

D.

Add the Multiple Hostnames filter and enter your list of hostnames

Questions # 19:

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

Options:

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

Questions # 20:

How do you enable Falcon to quarantine files?

Options:

A.

Through Prevention policy settings

B.

Through General Settings

C.

Through manual file deletion

D.

Through system restore

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.