CrowdStrike Certified Falcon Administrator - 2024 Version (CCFA-200b) Free Practice Test
Question 1
You are tasked with creating a "Workstations" host group to encompass all workstations in your environment.
Which dynamic grouping criteria will most efficiently accomplish this task?
Which dynamic grouping criteria will most efficiently accomplish this task?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
What default user role can manage API credentials?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 3
What is an example of when you will need to refer to your Customer ID+ Checksum (CIDC)?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 4
Which report provides a filterable high-level overview of host information such as OS version, Device Type and Machine Domain, and also provides an active sensor heat map for a quick environment review?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
Using Host setup and management inside the Falcon Console, how can you display sensors in Reduced Functionality Mode?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 6
To test a new Falcon sensor version, you have created a new sensor update policy and two separate dynamic host groups. One group contains all test Windows servers. The other group contains all of your Windows servers. The new policy was applied to only the test Windows servers host group. What is required to safely and successfully test your new sensor update policy on only your test Windows servers?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 7
What is the primary purpose of audit logs in Falcon?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
Which report would show you an overview of the top ten most-applied policies by sensors in your environment?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 9
Your leadership wants controls in place for immediate action on any OverWatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).