Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free CrowdStrike CCFA-200 Practice Exam with Questions & Answers | Set: 2

Questions 11

When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?

Options:
A.

Username

B.

Model

C.

Domain

D.

Hostname

CrowdStrike CCFA-200 Premium Access
Questions 12

Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?

Options:
A.

\Program Files\My Program\My Files\*

B.

\Program Files\My Program\*

C.

*\*

D.

*\Program Files\My Program\*\

Questions 13

What is the maximum number of patterns that can be added when creating a new exclusion?

Options:
A.

10

B.

0

C.

1

D.

5

Questions 14

When a host belongs to more than one host group, how is sensor update precedence determined?

Options:
A.

Groups have no impact on sensor update policies

B.

Sensors of hosts that belong to more than one group must be manually updated

C.

The highest precedence policy from the most important group is applied to the host

D.

All of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host

Questions 15

What three things does a workflow condition consist of?

Options:
A.

A parameter, an operator, and a value

B.

A beginning, a middle, and an end

C.

Triggers, actions, and alerts

D.

Notifications, alerts, and API's

Questions 16

How does the Unique Hosts Connecting to Countries Map help an administrator?

Options:
A.

It highlights countries with known malware

B.

It helps visualize global network communication

C.

It identifies connections containing threats

D.

It displays intrusions from foreign countries

Questions 17

One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?

Options:
A.

USB Device Policy

B.

Firewall Rule Group

C.

Containment Policy

D.

Machine Learning Exclusions

Questions 18

An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?

Options:
A.

Custom Alert History

B.

Workflow Execution log

C.

Workflow Audit log

D.

Falcon UI Audit Trail

Questions 19

Where can you modify settings to permit certain traffic during a containment period?

Options:
A.

Prevention Policy

B.

Host Settings

C.

Containment Policy

D.

Firewall Settings

Questions 20

You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?

Options:
A.

Contact support and request that they modify the Machine Learning settings to no longer include this detection

B.

Using IOC Management, add the hash of the binary in question and set the action to "Allow"

C.

Using IOC Management, add the hash of the binary in question and set the action to "Block, hide detection"

D.

Using IOC Management, add the hash of the binary in question and set the action to "No Action"

Exam Code: CCFA-200
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Certified Falcon Administrator
Last Update: Jul 11, 2025
Questions: 153

CrowdStrike Related Exams

CrowdStrike Free Exams

CrowdStrike Free Exams
Examstrack provides free CrowdStrike exam prep materials and practice tests to support your CrowdStrike certification goals.