CCFA-200 Exam Details

  • Exam Code
    :CCFA-200
  • Exam Name
    :CrowdStrike Certified Falcon Administrator
  • Certification
    :CrowdStrike Certifications
  • Vendor
    :CrowdStrike
  • Total Questions
    :186 Q&As
  • Last Updated
    :Oct 26, 2025

CrowdStrike CCFA-200 Online Questions & Answers

  • Question 71:

    How long are detection events kept in Falcon?

    A. Detection events are kept for 90 days
    B. Detections events are kept for your subscribed data retention period
    C. Detection events are kept for 7 days
    D. Detection events are kept for 30 days

  • Question 72:

    Why is the ability to disable detections helpful?

    A. It gives users the ability to set up hosts to test detections and later remove them from the console
    B. It gives users the ability to uninstall the sensor from a host
    C. It gives users the ability to allowlist a false positive detection
    D. It gives users the ability to remove all data from hosts that have been uninstalled

  • Question 73:

    Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?

    A. Real Time Responder
    B. Endpoint Manager
    C. Falcon Investigator
    D. Remediation Manager

  • Question 74:

    How can a Falcon Administrator configure a pop-up message to be displayed on a host when the Falcon sensor blocks, kills or quarantines an activity?

    A. By ensuring each user has set the "pop-ups allowed" in their User Profile configuration page
    B. By enabling "Upload quarantined files" in the General Settings configuration page
    C. By turning on the "Notify End Users" setting at the top of the Prevention policy details configuration page
    D. By selecting "Enable pop-up messages" from the User configuration page

  • Question 75:

    While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?

    A. Configure a Real Time Response policy allowlist with the specific IP addresses
    B. Configure a Containment Policy with the specific IP addresses
    C. Configure a Containment Policy with the entire internal IP CIDR block
    D. Configure the Host firewall to allowlist the specific IP addresses

  • Question 76:

    Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?

    A. TCP port 22 (SSH)
    B. TCP port 443 (HTTPS)
    C. TCP port 80 (HTTP)
    D. TCP UDP port 53 (DNS)

  • Question 77:

    Which is the correct order for manually installing a Falcon Package on a macOS system?

    A. Install the Falcon package, then register the Falcon Sensor via the registration package
    B. Install the Falcon package, then register the Falcon Sensor via command line
    C. Register the Falcon Sensor via command line, then install the Falcon package
    D. Register the Falcon Sensor via the registration package, then install the Falcon package

  • Question 78:

    During a sensor installation, what unique identifier is given to each sensor?

    A. Agent ID (AID)
    B. Security ID (SID)
    C. Computer ID (CID)
    D. Endpoint ID (EID)

  • Question 79:

    Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?

    A. Use the Sensor Report to filter to the specific endpoint
    B. Use the Investigate > Host Search to filter to the specific endpoint
    C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details
    D. From a command line, run the sc query csagent -version command

  • Question 80:

    When creating new IOCs in IOC management, which of the following fields must be configured?

    A. Hash, Description, Filename
    B. Hash, Action and Expiry Date
    C. Filename, Severity and Expiry Date
    D. Hash, Platform and Action

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CrowdStrike exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCFA-200 exam preparations and CrowdStrike certification application, do not hesitate to visit our Vcedump.com to find your solutions here.