CCFA-200 Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Oct 26, 2025

CrowdStrike CCFA-200 Online Questions & Answers

  • Question 131:

    Why is it important to know your company's event data retention limits in the Falcon platform?

    A. This is not necessary; you simply select "All Time" in your query to search all data
    B. You will not be able to search event data into the past beyond your retention period
    C. Data such as process records are kept for a shorter time than event data
    D. Your query will require you to specify the data pool associated with the date you wish to search

  • Question 132:

    How do you assign a policy to a specific group of hosts?

    A. Create a group containing the desired hosts using "Static Assignment." Go to the Assigned Host Groups tab of the desired policy and dick "Add groups to policy." Select the desired Group(s).
    B. Assign a tag to the desired hosts in Host Management. Create a group with an assignment rule based on that tag. Go to the Assignment tab of the desired policy and click "Add Groups to Policy." Select the desired Group(s).
    C. Create a group containing the desired hosts using "Dynamic Assignment." Go to the Assigned Host Groups tab of the desired policy and select criteria such as OU, OS, Hostname pattern, etc.
    D. On the Assignment tab of the desired policy, select "Static" assignment. From the next window, select the desired hosts (using fitters if needed) and click Add.

  • Question 133:

    When editing an existing IOA exclusion, what can NOT be edited?

    A. The IOA name
    B. All parts of the exclusion can be changed
    C. The exclusion name
    D. The hosts groups

  • Question 134:

    Which statement is TRUE regarding disabling detections on a host?

    A. Hosts with detections disabled will not alert on blocklisted hashes or machine learning detections, but will still alert on lOA-based detections. It will remain that way until detections are enabled again
    B. Hosts with detections disabled will not alert on anything until detections are enabled again
    C. Hosts with detections disabled will not alert on anything for 24 hours (by default) or longer if that setting is changed
    D. Hosts cannot have their detections disabled individually

  • Question 135:

    The alignment of a particular prevention policy to one or more host groups can be completed in which of the following locations within Falcon?

    A. Policy alignment is configured in the "Host Management" section in the Hosts application
    B. Policy alignment is configured only once during the initial creation of the policy in the "Create New Policy" pop-up window
    C. Policy alignment is configured in the General Settings section under the Configuration menu
    D. Policy alignment is configured in each policy in the "Assigned Host Groups" tab

  • Question 136:

    After agent installation, an agent opens a permanent___connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is terminated.

    A. SSH
    B. TLS
    C. HTTP
    D. TCP

  • Question 137:

    Which role allows a user to connect to hosts using Real-Time Response?

    A. Endpoint Manager
    B. Falcon Administrator
    C. Real Time Responder ?Active Responder
    D. Prevention Hashes Manager

  • Question 138:

    The Remote Access Graph in Visibility Reports displays:

    A. a bar chart where a bar represents a daily count of remote connections
    B. a geographical chart showing the geo-location of remote IP address
    C. a graph showing connections between hosts and users
    D. a pie chart showing a count per remote logon type

  • Question 139:

    To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?

    A. Blocking of Domains and IP addresses is not a function of IOC management. A Custom IOA Rule should be used instead
    B. Using IOC management, import the list of hashes and IP addresses and set the action to Detect Only
    C. Using IOC management, import the list of hashes and IP addresses and set the action to Prevent/Block
    D. Using IOC management, import the list of hashes and IP addresses and set the action to No Action

  • Question 140:

    You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?

    A. *nix
    B. Windows
    C. Both Windows and *nix
    D. Only Mac

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.