Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free CrowdStrike CCFA-200b Practice Exam with Questions & Answers | Set: 2

Questions 11

To improve the organization’s security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a new workflow from scratch, what component of the workflow must be configured first?

Options:
A.

Action

B.

Trigger

C.

Condition

D.

Workflow Name

CrowdStrike CCFA-200b Premium Access
Questions 12

What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?

Options:
A.

Hosts Overview

B.

Sensor Health

C.

Activity Overview

D.

Support and resources

Questions 13

You have 100 hashes that have been prohibited by management and need to be blocked within your organization. Using Falcon, what is the best way to accomplish this?

Options:
A.

Navigate to Configure > IOC Management. Add a custom IOC. Add the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.

B.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block. Verify Custom Execution Blocking is active.

C.

Navigate to Configure > IOC Management. Add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.

D.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block and Alert. Verify Custom Blocking inside Execution Blocking is active.

Questions 14

A member of your SECOPS team is building custom scripts for RTR, but they are unable to save or share them in Falcon. What additional role do they need?

Options:
A.

Real Time Response - Active Responder

B.

Real Time Response - Administrator

C.

Workflow Author

D.

Falcon Scripts Manager

Questions 15

What could cause your Windows host to be in Reduced Functionality Mode?

Options:
A.

The host lost internet connectivity

B.

CrowdStrike has not certified the latest Windows update

C.

The device was network contained

D.

A sensor update policy was misconfigured

Questions 16

You are deploying the Falcon sensor to 500 hosts. Hosts in an Organizational Unit need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter. What is the best way to create a host group for this OU?

Options:
A.

Create a Dynamic Group targeting Windows 10 OS in the domain

B.

Create a dynamic group with an assignment rule that excludes the OU

C.

Create a dynamic group with an assignment rule that filters for the OU

Questions 17

How are sensor updates managed and enforced across multiple hosts in Falcon?

Options:
A.

Prevention policies assigned to host groups

B.

Manual updates on each host

C.

Sensor update policies assigned to host groups

D.

Direct installation

Questions 18

When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?

Options:
A.

Customer ID and Integration ID

B.

Client ID and Secret

C.

Customer ID and Secret

D.

Client ID and OAuth2 ID

Questions 19

Where can you find a list of hosts that have not communicated with the CrowdStrike Cloud?

Options:
A.

Host Groups

B.

Inactive Sensors

C.

Activity Dashboard

D.

Sensor Report

Questions 20

What action should you take to securely allow operating system update processes to occur during network containment?

Options:
A.

Ensure all internal network IPs are allowed

B.

Add IPs of update sources to the Containment policy

C.

Add sources to the Host Firewall policy

D.

Remove network containment to allow access

Exam Code: CCFA-200b
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Falcon Certification Program
Last Update: May 23, 2026
Questions: 100