CrowdStrike CCFA-200 CrowdStrike Certified Falcon Administrator Online Training
CrowdStrike CCFA-200 Online Training
The questions for CCFA-200 were last updated at Apr 25,2025.
- Exam Code: CCFA-200
- Exam Name: CrowdStrike Certified Falcon Administrator
- Certification Provider: CrowdStrike
- Latest update: Apr 25,2025
Where do you obtain the Windows sensor installer for CrowdStrike Falcon?
- A . Sensors are downloaded from the Hosts > Sensor Downloads
- B . Sensor installers are unique to each customer and must be obtained from support
- C . Sensor installers are downloaded from the Support section of the CrowdStrike website
- D . Sensor installers are not used because sensors are deployed from within Falcon
Which of the following applies to Custom Blocking Prevention Policy settings?
- A . Hashes must be entered on the Prevention Hashes page before they can be blocked via this policy
- B . Blocklisting applies to hashes, IP addresses, and domains
- C . Executions blocked via hash blocklist may have partially executed prior to hash calculation process remediation may be necessary
- D . You can only blocklist hashes via the API
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?
- A . File exclusions are not aligned to groups or hosts
- B . There is a limit of three groups of hosts applied to any exclusion
- C . There is no limit and exclusions can be applied to any or all groups
- D . Each exclusion can be aligned to only one group of hosts
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
- A . There may be special considerations for each OS
- B . To assist with testing and tracking sensor rollouts
- C . The network protocols are different for each host OS
- D . It is an auditing requirement
What information is provided in Logan Activities under Visibility Reports?
- A . A list of all logons for all users
- B . A list of last endpoints that a user logged in to
- C . A list of users who are remotely logged on to devices based on local IP and local port
- D . A list of unique users who are remotely logged on to devices based on the country