Official Bank 0/151

CrowdStrike Certified Falcon Administrator (CCFA-200b) - CrowdStrike Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
151 Total Questions
1
Question
You want to create a detection-only policy. How do you set this up in your policy's settings?
Options
A Enable the detection sliders and disable the prevention sliders. Then ensure that Next Gen Antivirus is enabled so it will disable Windows Defender.
B Select the "Detect-Only" template. Disable hash blocking and exclusions.
C Set the Next-Gen Antivirus detection settings to the desired detection level and all the prevention sliders to disabled. Do not activate any of the other blocking or malware prevention options.
D You can't create a policy that detects but does not prevent. Use Custom IOA rules to detect.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
Options
A Prevention Policy Audit Trail
B Prevention Policy Debug
C Prevention Hashes Ignored
D Machine-Learning Prevention Monitoring
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
An analyst has reported they are not receiving workflow triggered notifications in the past few days.

Where should you first check for potential failures?
Options
A Custom Alert History
B Workflow Execution log
C Falcon UI Audit Trail
D Workflow Audit log
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
What is the maximum number of patterns that can be added when creating a new exclusion?
Options
A 10
B 0
C 1
D 5
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
What is the primary purpose of using glob syntax in an exclusion?
Options
A To specify a Domain be excluded from detections
B To specify exclusion patterns to easily exclude files and folders and extensions from detections
C To specify a network share be excluded from detections
D To specify exclusion patterns to easily add files and folders and extensions to be prevented
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.