Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free CrowdStrike CCFA-200b Practice Exam with Questions & Answers | Set: 3

Questions 21

You are assigning sensor group tags during installation. What is the maximum allowed length of all tags?

Options:
A.

237 characters

B.

256 characters

C.

50 characters

D.

100 characters

CrowdStrike CCFA-200b Premium Access
Questions 22

In order to receive the most stable sensor updates, what level of automatic sensor updates should be applied to a host?

Options:
A.

Auto-N-2

B.

Auto-N-1

C.

Pinned sensor version

D.

Auto-Latest

Questions 23

What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?

Options:
A.

RFM sensors on Linux hosts only send detection information to the Falcon Console. Event processing is disabled

B.

RFM sensors on Linux hosts stop processing both events and detections. Sensors send basic status information to the Falcon Console

C.

RFM sensors on Linux hosts continue to process events and detections for existing policies but cannot get policy updates from the Falcon Console

D.

RFM sensors on Linux hosts stop processing events and detections but continue to send log data into Falcon

Questions 24

During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?

Options:
A.

Put-and-Run is not enabled in the response policy

B.

Custom Scripts is not enabled in the response policy

C.

Script-Based Execution Monitoring is not enabled in the prevention policy

D.

The responder requires the RTR Administrator role

Questions 25

A new prevention policy has been created for assignment to the group named “Servers”. When you try to apply the policy, the “Servers” group is not available. What is the most likely reason the group is not available?

Options:
A.

The “Servers” group must be disabled first

B.

The “Servers” group already has a prevention policy applied to it

C.

Host type was not defined correctly within the prevention policy

D.

The new prevention policy should be enabled first

Questions 26

What type of information is provided in sensor health report?

Options:
A.

User login history

B.

Local performance metrics

C.

Current operational status

D.

Network traffic patterns

Questions 27

When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?

Options:
A.

Access Key and Secret Key

B.

Integration Key and Customer ID

C.

API Client and Secret Key

D.

OAuth2 Token and Client Secret

Questions 28

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?

Options:
A.

Create an exclusion for the felix.dll file

B.

Create an IOA exclusion for C:\Users\Bob\DevCode\felix.dll

C.

Create a separate Host Group for development machines and apply a less restrictive policy

D.

Create a Custom IOC and set it to Allow for C:\Users\Bob\DevCode\felix.dll

Questions 29

Which ML exclusion pattern would be the most accurate for all .exe binaries in “C:\Program Files\Software\”, including any subfolders of Software?

Options:
A.

Program Files\Software* .exe

B.

Program Files\Software*.exe

C.

Program Files\Software* *.exe

D.

***.exe

Questions 30

What is the primary concern with Windows sensors going into Reduced Functionality Mode?

Options:
A.

The sensors are unable to report any of their recorded events

B.

The sensors do not have full visibility into all events occurring on the host

C.

The hosts have been powered off or otherwise cannot communicate with the Falcon cloud

D.

The operating systems on these hosts have crashed

Exam Code: CCFA-200b
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Falcon Certification Program
Last Update: May 23, 2026
Questions: 100