Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
When editing an existing IOA exclusion, what can NOT be edited?
When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as ''Suspicious Process Execution - Script Interpreter Executing File''. The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform.However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria2.
Which of the following is TRUE of the Logon Activities Report?
The Logon Activities Report shows a graphical view of user logon activity and the hosts the user connected to, but it only gives a summary of the last logon activity for users. It does not give a detailed list of all logon activity for users, nor can it be filtered by computer name. The other options are either incorrect or not true of the report. Reference:CrowdStrike Falcon User Guide, page 50.
When a user initiates a sensor installs, where can the logs be found?
When a user initiates a sensor install, the logs can be found in %SYSTEMROOT%\Temp. This folder contains temporary files and folders created by the system or applications, including the sensor installation logs. The sensor installation logs have names that start with CSFalconContainer and end with .log, such as CSFalconContainer-2023-08-31_11-23-21.log.These logs can help you troubleshoot any issues or errors that may occur during the sensor installation process3.
What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
The option that best describes what happens to detections in the console after clicking ''Disable Detections'' for a host from within the Host Management page is that the detections for the host are removed from the console immediately and no new detections will display in the console going forward. The ''Disable Detections'' feature allows you to enable or disable the detection and prevention capabilities of the Falcon sensor on a specific host. When you disable detections for a host, the sensor will stop sending any detection or prevention events to the Falcon console, and any existing events for that host will be removed from the console.When you enable detections for a host, the sensor will resume sending any new detection or prevention events to the Falcon console, but any previous events for that host will not be restored to the console1.
The Customer ID (CID) is important in which of the following scenarios?
The Customer ID (CID) is important in which of the following scenarios: when performing the sensor installation process and when setting up API keys. The CID is a unique identifier for your organization that is required for authenticating your sensor installation and communication with the Falcon cloud. You need to provide your CID when installing the Falcon sensor on a host, either by using a command-line parameter or by using the falconctl tool. The CID is also required for setting up API keys, which are used for accessing the Falcon platform programmatically via the Falcon APIs. You need to provide your CID when creating an API client and key in the API Clients and Keys page in the Falcon console.
153 questions covering all exam domains, starting from $20
Exam domains verified against: Official CrowdStrike CCFA-200b exam guide, last checked September 2026.
Determine roles and permissions required for Falcon console access. Create and assign roles to users while managing API keys for programmatic access. Understanding role-based access control ensures proper user provisioning and least privilege principles.
Identify prerequisites for successful sensor installation on supported operating systems. Apply best practice policies to prepare workloads and handle sensor uninstallation and troubleshooting. Proper deployment prevents configuration issues and reduces post-installation support problems.
Use filtering in Host Management to locate and organize endpoints. Understand Reduced Functionality Mode causes and impacts, and locate inactive sensors. Managing hosts effectively ensures you can track sensor health and diagnose connectivity problems quickly.
Determine appropriate group assignments for endpoints and understand how grouping affects policy application. Apply best practices when managing host groups to ensure consistent security policy enforcement. Groups serve as the foundation for policy inheritance and targeted management.
Configure prevention policies and sensor update policies to control endpoint behavior and update schedules. Set up containment policies with IP and subnet exclusions, manage quarantined files, and review RTR audit logs. Policy configuration directly impacts your security posture and operational stability.
Create custom IOA rules to monitor non-malicious behavior and assess IOC settings for security posturing. Interpret business requirements to allow trusted activity and resolve false positives. Custom rules let you tune detections to your environment and reduce alert fatigue.
Sample question from this domain above: Q2
Understand sensor reports, their use cases, and the different audit logs available in the platform. Reports reveal patterns and support compliance requirements while audit logs track administrative actions. Selecting the right report type helps you prove security effectiveness and investigate incidents.
Configure workflows to respond to defined triggers and automate response actions. Workflows reduce manual effort and ensure consistent incident response. Well-designed workflows accelerate detection-to-response time and integrate with your security operations.
Common questions about the exam itself