CrowdStrike CCFA-200b CrowdStrike Falcon Certification Program Exam Practice Test
CrowdStrike Falcon Certification Program Questions and Answers
When searching for a host network address, which IP notation should be used?
In order to quarantine files on the host, what prevention policy settings must be enabled?
You are tasked with creating a “Workstations” host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?
Which statement best describes user permissions in Falcon?
How are prevention policies assigned to hosts in the Falcon platform?
What information can be found in the Real Time Response (RTR) Audit Log?
After attempting to uninstall the Falcon sensor from a Windows endpoint, the process appears stuck. What troubleshooting step should be taken?
When an API client is created, what two pieces of information must be generated as a pair to successfully identify and validate your API integrations?
Why would you add IP addresses to a containment policy?
What is an example of when you will need to refer to your Customer ID+ Checksum (CIDC)?
You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?
What prevention policy setting prevents sensor-related files, folders, and registry objects from being renamed or deleted?
What policy setting should be selected for a new host when it has an existing antivirus?
What are the components that must be allowed to manually install Falcon Sensor on macOS?
What type of information is provided in sensor health report?
Which report in Falcon can be used to determine the volume of blocked activity at a different prevention policy setting?
Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to “C:\Users\Bob\DevCode\felix.dll”. In the detection, you see that it is triggering only on a specific Falcon IOA. What would be the best course of action for this situation?
During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?
An inactive host does not contact the Falcon cloud. What is the default number of days after which it is automatically removed from the Host Management page?
You are attempting to install the Falcon sensor on a host with a slow internet connection, and the installation fails after 20 minutes. What parameter can be used to override the 20-minute default provisioning window?
What action should you take to securely allow operating system update processes to occur during network containment?
In order to receive the most stable sensor updates, what level of automatic sensor updates should be applied to a host?
What prevention policy settings must be enabled to quarantine files on the host?
Which default user role will allow you to see all analyst session details?
After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?
Your leadership wants controls in place for immediate action on any OverWatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?
What update policy does a sensor receive when it does not have a group assignment?
Which ML exclusion pattern would be the most accurate for all .exe binaries in “C:\Program Files\Software\”, including any subfolders of Software?
What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?