CrowdStrike CCFA-200b Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 9, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

CrowdStrike CCFA-200b Exam Details

Key details for this exam, checked against the published exam outline

153 Practice Questions (Our Bank)
90 minutes Exam Duration
70% Passing Score
USD 250 Exam Fee
Exam Code
CCFA-200b
Full Name
CrowdStrike Certified Falcon Administrator
Issuing Body
CrowdStrike
Question Format (Our Bank)
Multiple Choice
Eligibility
Minimum six months hands-on experience with CrowdStrike Falcon in production environment
Practice Questions

Free CCFA-200b Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our CCFA-200b exam preparation team, who also write the explanation shown with each one. How we research and review these pages

When editing an existing IOA exclusion, what can NOT be edited?

Correct Answer: A
Explanation

When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as ''Suspicious Process Execution - Script Interpreter Executing File''. The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform.However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria2.

Which of the following is TRUE of the Logon Activities Report?

Correct Answer: D
Explanation

The Logon Activities Report shows a graphical view of user logon activity and the hosts the user connected to, but it only gives a summary of the last logon activity for users. It does not give a detailed list of all logon activity for users, nor can it be filtered by computer name. The other options are either incorrect or not true of the report. Reference:CrowdStrike Falcon User Guide, page 50.

When a user initiates a sensor installs, where can the logs be found?

Correct Answer: B
Explanation

When a user initiates a sensor install, the logs can be found in %SYSTEMROOT%\Temp. This folder contains temporary files and folders created by the system or applications, including the sensor installation logs. The sensor installation logs have names that start with CSFalconContainer and end with .log, such as CSFalconContainer-2023-08-31_11-23-21.log.These logs can help you troubleshoot any issues or errors that may occur during the sensor installation process3.

What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?

Correct Answer: A
Explanation

The option that best describes what happens to detections in the console after clicking ''Disable Detections'' for a host from within the Host Management page is that the detections for the host are removed from the console immediately and no new detections will display in the console going forward. The ''Disable Detections'' feature allows you to enable or disable the detection and prevention capabilities of the Falcon sensor on a specific host. When you disable detections for a host, the sensor will stop sending any detection or prevention events to the Falcon console, and any existing events for that host will be removed from the console.When you enable detections for a host, the sensor will resume sending any new detection or prevention events to the Falcon console, but any previous events for that host will not be restored to the console1.

The Customer ID (CID) is important in which of the following scenarios?

Correct Answer: B
Explanation

The Customer ID (CID) is important in which of the following scenarios: when performing the sensor installation process and when setting up API keys. The CID is a unique identifier for your organization that is required for authenticating your sensor installation and communication with the Falcon cloud. You need to provide your CID when installing the Falcon sensor on a host, either by using a command-line parameter or by using the falconctl tool. The CID is also required for setting up API keys, which are used for accessing the Falcon platform programmatically via the Falcon APIs. You need to provide your CID when creating an API client and key in the API Clients and Keys page in the Falcon console.

Get Full Access

153 questions covering all exam domains, starting from $20

Study Guide

What the CrowdStrike CCFA-200b Exam Covers

Exam domains verified against: Official CrowdStrike CCFA-200b exam guide, last checked September 2026.

Domain 1: User Management

Determine roles and permissions required for Falcon console access. Create and assign roles to users while managing API keys for programmatic access. Understanding role-based access control ensures proper user provisioning and least privilege principles.

Domain 2: Sensor Deployment

Identify prerequisites for successful sensor installation on supported operating systems. Apply best practice policies to prepare workloads and handle sensor uninstallation and troubleshooting. Proper deployment prevents configuration issues and reduces post-installation support problems.

Domain 3: Host Management and Setup

Use filtering in Host Management to locate and organize endpoints. Understand Reduced Functionality Mode causes and impacts, and locate inactive sensors. Managing hosts effectively ensures you can track sensor health and diagnose connectivity problems quickly.

Domain 4: Group Creation

Determine appropriate group assignments for endpoints and understand how grouping affects policy application. Apply best practices when managing host groups to ensure consistent security policy enforcement. Groups serve as the foundation for policy inheritance and targeted management.

Sample questions from this domain above: Q3Q4

Domain 5: Policy Application

Configure prevention policies and sensor update policies to control endpoint behavior and update schedules. Set up containment policies with IP and subnet exclusions, manage quarantined files, and review RTR audit logs. Policy configuration directly impacts your security posture and operational stability.

Sample questions from this domain above: Q1Q5

Domain 6: Rules Configuration

Create custom IOA rules to monitor non-malicious behavior and assess IOC settings for security posturing. Interpret business requirements to allow trusted activity and resolve false positives. Custom rules let you tune detections to your environment and reduce alert fatigue.

Sample question from this domain above: Q2

Domain 7: Dashboards and Reports

Understand sensor reports, their use cases, and the different audit logs available in the platform. Reports reveal patterns and support compliance requirements while audit logs track administrative actions. Selecting the right report type helps you prove security effectiveness and investigate incidents.

Domain 8: Workflows

Configure workflows to respond to defined triggers and automate response actions. Workflows reduce manual effort and ensure consistent incident response. Well-designed workflows accelerate detection-to-response time and integrate with your security operations.

FAQ

CCFA-200b Exam FAQ

Common questions about the exam itself

What experience do I need before taking the CCFA-200b exam?
You should have at least six months of hands-on experience using CrowdStrike Falcon in a production environment. This practical experience helps you understand how the platform works in real deployments and prepares you for scenario-based exam questions.
How many questions are on the CCFA-200b exam and how long do I have?
The exam contains 60 questions and you have 90 minutes to complete it. This gives you roughly 90 seconds per question on average, so time management and quick decision making matter.
What score do I need to pass the CCFA-200b?
You need to score at least 70% to pass. This means you can miss up to 18 questions out of 60 and still pass the exam.
What is the most challenging part of the CCFA-200b exam?
User Management and Policy Application tend to be difficult because they involve understanding role-based access control, permission inheritance, and how policies cascade through host groups. Spending lab time with actual role creation and policy configuration helps you master these areas.
How long should I study to prepare for CCFA-200b?
If you already have the required six months of hands-on experience, two to four weeks of focused study with one to two hours per day is typical. Without that experience, you may need four to eight weeks to become familiar with the platform.
Can I retake the CCFA-200b exam if I fail?
Yes, you can retake the exam up to four times. If you fail a fourth attempt due to technical issues, you may get a fifth attempt. If you fail due to personal performance, you must wait 30 days and retake the recommended training before a fifth attempt.
How long does the CCFA-200b certification stay valid?
The validity period is not published on the official CrowdStrike exam guide page we consulted. Check the CrowdStrike University portal for current renewal or expiration details.
What job role is the CCFA-200b certification designed for?
The CCFA-200b is designed for system administrators and cybersecurity analysts who manage the administrative features of the CrowdStrike Falcon platform. It validates your ability to deploy, configure, manage policies, and handle user access.
What question formats appear on the CCFA-200b exam?
The exam includes multiple choice, multiple answer, and drag and drop questions. This variety tests both knowledge recall and practical understanding of how Falcon features work together.
Is the CCFA-200b the only CrowdStrike certification exam?
No, CrowdStrike offers a broader Falcon Certification Program that includes roles for administrators, front-line responders, investigators, cloud security specialists, and identity protection specialists. The CCFA-200b is the foundational administrator certification.