Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CCFA-200b Premium Access

View all detail and faqs for the CCFA-200b exam


443 Students Passed

92% Average Score

91% Same Questions
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

What prevention policy settings must be enabled to quarantine files on the host?

Options:

A.

Quarantine Files; Windows Anti-Malware Execution Blocking

B.

Malware Protection; Custom Execution Blocking

C.

Next-Gen Antivirus Prevention sliders; Quarantine & Security Center Registration

D.

Advanced Remediation Actions; Quarantine level set to Aggressive

Questions # 22:

In order to receive the most stable sensor updates, what level of automatic sensor updates should be applied to a host?

Options:

A.

Auto-N-2

B.

Auto-N-1

C.

Pinned sensor version

D.

Auto-Latest

Questions # 23:

What update policy does a sensor receive when it does not have a group assignment?

Options:

A.

Top precedence policy

B.

Default policy

C.

Auto N-1 policy

Questions # 24:

When searching for a host network address, which IP notation should be used?

Options:

A.

10 10105,1010108

B.

1010102,10 10107

C.

192.168.5.1/24

D.

192 168 5 1-100

Questions # 25:

A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

B.

Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools

C.

Remove Host containment and update the host with all patches

D.

Create a Firewall Policy that allow lists your patch management tools

Questions # 26:

What could cause your Windows host to be in Reduced Functionality Mode?

Options:

A.

The host lost internet connectivity

B.

CrowdStrike has not certified the latest Windows update

C.

The device was network contained

D.

A sensor update policy was misconfigured

Questions # 27:

Where can you find hosts that have been offline for ten minutes or longer?

Options:

A.

Host Management

B.

Sensor Coverage Dashboard

C.

Host Groups

Questions # 28:

What is true about User Accounts created by the Falcon Administrator?

Options:

A.

By default, all User Accounts are created with the Falcon Analyst role

B.

All new User Accounts are created using an employee identification number

C.

All User Accounts must start with the domain identifier and number

D.

All User Accounts must be created with an email address from the list of approved domains

Questions # 29:

After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?

Options:

A.

Falcon requires a 24-hour waiting period to apply custom policies to newly installed hosts

B.

A host-based firewall rule is preventing the custom policy from applying successfully

C.

The laptop is not a member of a host group assigned to the custom policy

D.

A prompt to apply the new prevention policy was manually declined

Questions # 30:

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

Options:

A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

B.

Implement an SVE on the particular host

C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done

D.

Use Real Time Response to kill the offending process on the server

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.