Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free CrowdStrike CCFA-200 Practice Exam with Questions & Answers | Set: 4

Questions 31

Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?

Options:
A.

Real Time Responder

B.

Endpoint Manager

C.

Falcon Investigator

D.

Remediation Manager

CrowdStrike CCFA-200 Premium Access
Questions 32

Why would you assign hosts to a static group instead of a dynamic group?

Options:
A.

You do not want the group membership to change automatically

B.

You are managing more than 1000 hosts

C.

You need hosts to be automatically assigned to a group

D.

You want the group to contain hosts from multiple operating systems

Questions 33

Which role allows a user to connect to hosts using Real-Time Response?

Options:
A.

Endpoint Manager

B.

Falcon Administrator

C.

Real Time Responder – Active Responder

D.

Prevention Hashes Manager

Questions 34

Where in the Falcon console can information about supported operating system versions be found?

Options:
A.

Configuration module

B.

Intelligence module

C.

Support module

D.

Discover module

Questions 35

How do you find a list of inactive sensors?

Options:
A.

The Falcon platform does not provide reporting for inactive sensors

B.

A sensor is always considered active until removed by an Administrator

C.

Run the Inactive Sensor Report in the Host setup and management option

D.

Run the Sensor Aging Report within the Investigate option

Questions 36

Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?

Options:
A.

.*badguydomain.com.*

B.

\Device\HarddiskVolume2\*.exe -SingleArgument <a href="www.badguydomain.com">www.badguydomain.com</a> /kill

C.

badguydomain\.com.*

D.

Custom IOA rules cannot be created for domains

Questions 37

When creating new IOCs in IOC management, which of the following fields must be configured?

Options:
A.

Hash, Description, Filename

B.

Hash, Action and Expiry Date

C.

Filename, Severity and Expiry Date

D.

Hash, Platform and Action

Questions 38

What is the purpose of precedence with respect to the Sensor Update policy?

Options:
A.

Precedence applies to the Prevention policy and not to the Sensor Update policy

B.

Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)

C.

Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)

D.

Precedence ensures that conflicting policy settings are not set in the same policy

Questions 39

On which page of the Falcon console can one locate the Customer ID (CID)?

Options:
A.

Hosts Management

B.

API Clients and Keys

C.

Sensor Dashboard

D.

Sensor Downloads

Questions 40

What is the function of a single asterisk (*) in an ML exclusion pattern?

Options:
A.

The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path

B.

The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path

C.

The single asterisk is the insertion point for the variable list that follows the path

D.

The single asterisk is only used to start an expression, and it represents the drive letter

Exam Code: CCFA-200
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Certified Falcon Administrator
Last Update: Jul 13, 2025
Questions: 153

CrowdStrike Related Exams

CrowdStrike Free Exams

CrowdStrike Free Exams
Examstrack provides free CrowdStrike exam prep materials and practice tests to support your CrowdStrike certification goals.