Spring Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the CrowdStrike Falcon Certification Program CCFA-200b Questions and answers with Dumpstech

Exam CCFA-200b Premium Access

View all detail and faqs for the CCFA-200b exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

From the Host management page, what is the best field to filter by for Domain Controllers to obtain sensor version information?

Options:

A.

Sensor Version

B.

Type

C.

Platform

D.

OS Version

Questions # 22:

A host has been Network Contained with Falcon and you have been asked to urgently update the Operating System with patches. You have tried using your patch update systems, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

Options:

A.

Create a Containment Policy that allow lists the FQDN of your patch management tools

B.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

C.

Adjust the Content Update Policies to Early Access with No Delay

D.

Create an IP group in IP Allowlist Management

Questions # 23:

What log would you use to investigate unusual activity invoked with a script interfacing with the Falcon platform?

Options:

A.

Falcon UI audit

B.

RTR session audit

C.

Prevention policy debug

D.

API audit

Questions # 24:

Which Windows prevention policy setting monitors contents of shells for execution of malicious content?

Options:

A.

Script-based execution visibility

B.

Suspicious Scripts and Commands

C.

Enhanced exploitation visibility

D.

Additional user mode data visibility

Questions # 25:

You have created a new static host group to test a newly created sensor update policy, and need to add 500 servers into the group. You want to upload a list of hosts to Falcon for automatic addition into the group. What file format must the list be for this to be successfully accomplished?

Options:

A.

XLSX

B.

PDF

C.

TXT

D.

JSON

Questions # 26:

What are the three required parts of a Fusion SOAR workflow condition?

Options:

A.

Operator, value, and source

B.

Alert, action, and schedule

C.

Trigger, parameter, and alert

D.

Parameter, operator, and value

Questions # 27:

An inactive host does not contact the Falcon cloud. What is the default number of days after which it is automatically removed from the Host Management page?

Options:

A.

30 Days

B.

90 Days

C.

45 Days

Questions # 28:

You are tasked with creating a “Workstations” host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?

Options:

A.

OU Workstation

B.

Grouping Tags Workstation

C.

Type: Workstation

D.

Platform Windows

Questions # 29:

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

Options:

A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled

B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console

C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console

D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon

Questions # 30:

You are deploying the Falcon sensor to 500 hosts. Hosts in an Organizational Unit need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter. What is the best way to create a host group for this OU?

Options:

A.

Create a Dynamic Group targeting Windows 10 OS in the domain

B.

Create a dynamic group with an assignment rule that excludes the OU

C.

Create a dynamic group with an assignment rule that filters for the OU

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions