Pre-Summer Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

Page: 1 / 3
Total 30 questions
Exam Code: CCFA-200b                Update: May 26, 2026
Exam Name: CrowdStrike Falcon Certification Program

CrowdStrike CrowdStrike Falcon Certification Program CCFA-200b Exam Dumps: Updated Questions & Answers (May 2026)

Question # 1

What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?

A.

It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

B.

It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

C.

It is designed to show malicious processes that would have been blocked in your environment based on different Machine-Learning Prevention settings

D.

It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

Question # 2

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to “C:\Users\Bob\DevCode\felix.dll”. In the detection, you see that it is triggering only on a specific Falcon IOA. What would be the best course of action for this situation?

A.

Create an IOA exclusion for “C:\Users\Bob\DevCode\felix.dll”

B.

Create a Custom IOC and set it to “Allow” for “C:\Users\Bob\DevCode\felix.dll”

C.

Manually turn off the built-in IOA through prevention policies

D.

Create a sensor visibility exclusion for “C:\Users\Bob\DevCode\felix.dll”

Question # 3

Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?

A.

Create an exclusion for the felix.dll file

B.

Create an IOA exclusion for C:\Users\Bob\DevCode\felix.dll

C.

Create a separate Host Group for development machines and apply a less restrictive policy

D.

Create a Custom IOC and set it to Allow for C:\Users\Bob\DevCode\felix.dll

Question # 4

What is the fastest way to locate inactive sensors in the Falcon console?

A.

Sort hosts by Last Seen timestamp

B.

Export all host data to CSV

C.

Filter the Host Management page to show inactive hosts

D.

Search for hosts with no Agent ID

Question # 5

When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?

A.

Access Key and Secret Key

B.

Integration Key and Customer ID

C.

API Client and Secret Key

D.

OAuth2 Token and Client Secret

Question # 6

What are the three required parts of a Fusion SOAR workflow condition?

A.

Operator, value, and source

B.

Alert, action, and schedule

C.

Trigger, parameter, and alert

D.

Parameter, operator, and value

Question # 7

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

Question # 8

What log would you use to investigate unusual activity invoked with a script interfacing with the Falcon platform?

A.

Falcon UI audit

B.

RTR session audit

C.

Prevention policy debug

D.

API audit

Question # 9

Where would you apply a configuration to allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained?

A.

IP Allowlist Management

B.

Containment Policy

C.

Response Policies

D.

Maintenance Token

Question # 10

After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?

A.

Falcon requires a 24-hour waiting period to apply custom policies to newly installed hosts

B.

A host-based firewall rule is preventing the custom policy from applying successfully

C.

The laptop is not a member of a host group assigned to the custom policy

D.

A prompt to apply the new prevention policy was manually declined

Page: 1 / 3
Total 30 questions

Most Popular Certification Exams

Payment

       

Contact us

Site Secure

mcafee secure

TESTED 26 May 2026