Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free CrowdStrike CCFA-200 Practice Exam with Questions & Answers | Set: 3

Questions 21

Once an exclusion is saved, what can be edited in the future?

Options:
A.

All parts of the exclusion can be changed

B.

Only the selected groups and hosts to which the exclusion is applied can be changed

C.

Only the options to "Detect/Block" and/or "File Extraction" can be changed

D.

The exclusion pattern cannot be changed

CrowdStrike CCFA-200 Premium Access
Questions 22

What is the purpose of the Machine-Learning Prevention Monitoring Report?

Options:
A.

It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

B.

It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

C.

It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

D.

It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings

Questions 23

Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?

Options:
A.

TCP port 22 (SSH)

B.

TCP port 443 (HTTPS)

C.

TCP port 80 (HTTP)

D.

TCP UDP port 53 (DNS)

Questions 24

You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?

Options:
A.

Specific sensor version number

B.

Auto - TEST-QA

C.

Sensor version updates off

D.

Auto - N-1

Questions 25

You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?

Options:
A.

Using the Support Portal, create a support ticket and include the list of binary hashes, asking support to create an "Execution Prevention" rule to prevent these processes from running

B.

Using Custom Alerts in the Investigate App, create a new alert using the template "Process Execution" and within that rule, select the option to "Block Execution"

C.

Using IOC Management, gather the list of SHA256 or MD5 hashes for each binary and then upload them. Set all hashes to "Block" and ensure that the prevention policy these computers are using includes the option for "Custom Blocking" under Execution Blocking.

D.

Using the API, gather the list of SHA256 or MD5 hashes for each binary and then upload them, setting them all to "Never Allow"

Questions 26

Which of the following can a Falcon Administrator edit in an existing user's profile?

Options:
A.

First or Last name

B.

Phone number

C.

Email address

D.

Working groups

Questions 27

What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?

Options:
A.

The detections for the host are removed from the console immediately and no new detections will display in the console going forward

B.

You cannot disable detections for a host

C.

Existing detections for the host remain, but no new detections will display in the console going forward

D.

Preventions will be disabled for the host

Questions 28

Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?

Options:
A.

Sensor Visibility Exclusion

B.

Machine Learning Exclusions

C.

IOC Exclusions

D.

IOA Exclusions

Questions 29

What statement is TRUE about managing a user's role?

Options:
A.

The Administrator cannot re-use the account email for a new account

B.

You must have Falcon MFA enabled first

C.

You must be a Falcon Security Lead

D.

You must be a Falcon Administrator

Questions 30

To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

Options:
A.

Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead

B.

Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only

C.

Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block

D.

Using IOC management, import the list of hashes and IP addresses and set the action to No Action

Exam Code: CCFA-200
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Certified Falcon Administrator
Last Update: Jul 13, 2025
Questions: 153

CrowdStrike Related Exams

CrowdStrike Free Exams

CrowdStrike Free Exams
Examstrack provides free CrowdStrike exam prep materials and practice tests to support your CrowdStrike certification goals.