CCFA-200 Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Oct 26, 2025

CrowdStrike CCFA-200 Online Questions & Answers

  • Question 101:

    Which of the following is TRUE of the Logon Activities Report?

    A. Shows a graphical view of user logon activity and the hosts the user connected to
    B. The report can be filtered by computer name
    C. It gives a detailed list of all logon activity for users
    D. It only gives a summary of the last logon activity for users

  • Question 102:

    You want to create a detection-only policy. How do you set this up in your policy's settings?

    A. Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.
    B. Select the "Detect-Only" template. Disable hash blocking and exclusions.
    C. You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.
    D. Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.

  • Question 103:

    Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to, "C:\Users\Bob\DevCode\felix.dll". In the detection, you see that it's triggering only on a specific Falcon IOA. What would be the best course of action for this situation?

    A. Create a sensor visibility exclusion for "C:\Users\Bob\DevCode\felix.dll"
    B. Create an IOA exclusion for "C:\Users\Bob\DevCode\felix.dll"
    C. Create a Custom IOC and set it to "Allow" for "C:\Users\Bob\DevCode\felix.dll"
    D. Manually turn off the built-in IOA through prevention policies

  • Question 104:

    Which of the following controls the speed in which your sensors will receive automatic sensor updates?

    A. Maintenance Tokens
    B. Sensor Update Policy
    C. Sensor Update Throttling
    D. Channel File Update Throttling

  • Question 105:

    How would an installation token be configured if the Falcon Sensor was installed on a Red Hat Enterprise Linux host?

    A. You will be prompted to enter the installation token during the install if it is required
    B. sudo yum install --cid= --provisioning-token=ABCD1234
    C. sudo /opt/CrowdStrike/falconctl -s -t ABCD1234
    D. sudo /opt/CrowdStrike/falconctl -s --cid= --provisioning-token=ABCD1234

  • Question 106:

    A sensor that has not contacted the Falcon cloud will be automatically deleted from the hosts list after how many days?

    A. 45 Days
    B. 60 Days
    C. 30 Days
    D. 90 Days

  • Question 107:

    How are user permissions set in Falcon?

    A. Permissions are assigned to a User Group and then users are assigned to that group, thereby inheriting those permissions
    B. Pre-defined permissions are assigned to sets called roles. Users can be assigned multiple roles based on job function and they assume a cumulative set of permissions based on those assignments
    C. An administrator selects individual granular permissions from the Falcon Permissions List during user creation
    D. Permissions are token-based. Users request access to a defined set of permissions and an administrator adds their token to the set of permissions

  • Question 108:

    The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. What must you ensure is disabled for the sensor to communicate with the CrowdStrike Cloud?

    A. Proxy information
    B. Deep packet inspection
    C. NMAP scanning
    D. TCP inspection

  • Question 109:

    One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?

    A. USB Device Policy
    B. Firewall Rule Group
    C. Containment Policy
    D. Machine Learning Exclusions

  • Question 110:

    What is the primary purpose of using glob syntax in an exclusion?

    A. To specify a Domain be excluded from detections
    B. To specify exclusion patterns to easily exclude files and folders and extensions from detections
    C. To specify exclusion patterns to easily add files and folders and extensions to be prevented
    D. To specify a network share be excluded from detections

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.