Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

CrowdStrike Falcon Certification Program

Last Update 3 hours ago Total Questions : 100

The CrowdStrike Falcon Certification Program content is now fully updated, with all current exam questions added 3 hours ago. Deciding to include CCFA-200b practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CCFA-200b exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CCFA-200b sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any CrowdStrike Falcon Certification Program practice test comfortably within the allotted time.

Question # 11

Which role allows a Falcon user to create Real Time Response Custom Scripts?

A.

Real Time Responder – Active Responder

B.

Real Time Responder – Administrator

C.

Real Time Responder – Read Only Analyst

D.

Real Time Responder – Script Developer

Question # 12

In order to prevent duplicate Agent IDs, what install parameter should be used on VMs to be used as persistent clones?

A.

ProvNoWait=1

B.

VDI=true

C.

NO_START=1

D.

VM=True

Question # 13

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

A.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

B.

Implement an SVE on the particular host

C.

Temporarily disable detections for the server in Host Management and re-enable after the test is done

D.

Use Real Time Response to kill the offending process on the server

Question # 14

A new prevention policy has been created for assignment to the group named “Servers”. When you try to apply the policy, the “Servers” group is not available. What is the most likely reason the group is not available?

A.

The “Servers” group must be disabled first

B.

The “Servers” group already has a prevention policy applied to it

C.

Host type was not defined correctly within the prevention policy

D.

The new prevention policy should be enabled first

Question # 15

Excluding mobile devices, what kind of hosts can be contained in Falcon?

A.

Windows and MacOS hosts running the Falcon sensor

B.

Windows and Linux hosts running the Falcon sensor

C.

Windows, Linux, and container hosts running the Falcon sensor

D.

Windows, Linux, and MacOS hosts running the Falcon sensor

Question # 16

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled

B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console

C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console

D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon

Question # 17

Your incident responder team is migrating existing workflows into Fusion SOAR workflows so that they execute natively in Falcon. The workflow imports are failing. What format must the workflows be in order to successfully import them into Fusion SOAR?

A.

YAML

B.

CSV

C.

SOAR

D.

JSON

Question # 18

During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?

A.

Put-and-Run is not enabled in the response policy

B.

Custom Scripts is not enabled in the response policy

C.

Script-Based Execution Monitoring is not enabled in the prevention policy

D.

The responder requires the RTR Administrator role

Question # 19

You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that it executes successfully?

A.

Trigger, Condition, Action

B.

Rule Type, Condition, Action

C.

Rule Type, Filter, Objective

D.

Trigger, Filter, Objective

Question # 20

Why would you add IP addresses to a containment policy?

A.

You want to automate the Network Containment process based on the IP address of a host

B.

A new group of analysts need to be able to place hosts under Network Containment

C.

Your organization has resources that need to be accessible when hosts are network contained

D.

Your organization has additional IP addresses that need to be able to access the Falcon console

Go to page: