You need to be aware of which policies are the most used as new hosts are being added to your CID. Where will you find a review of the top-ten sensor update, prevention, and device control policies?
Correct Answer: C
The best answer is Managed Assets dashboard . This dashboard-oriented view is used for operational visibility across managed endpoints and helps administrators understand how assets are distributed across important attributes, including policy-related coverage. The question asks for a "top-ten" review of sensor update, prevention, and device control policies as new hosts are added to the CID, which aligns with dashboard summarization rather than a per-host daily report. The Sensor Policy Daily Report is useful for reviewing assigned groups and policies for hosts, but it is not the best answer for a high-level top-ten usage review. Executive Summary is broader leadership reporting, not the operational location for policy-use distribution across managed assets. The CCFA reporting objective here is policy coverage awareness at scale.
CCFA-200b Exam Question 2
What happens when a Falcon Sensor on a Linux host enters Reduced Functionality Mode?
Correct Answer: B
When a Linux sensor enters RFM, it stops processing both events and detections, but it continues sending basic status information such as SensorHeartBeat events to indicate that the sensor is installed. Linux RFM is more restrictive than Windows RFM. On Windows, the sensor may still monitor and report at reduced capacity, but on Linux, unsupported kernel or user-mode requirements can result in no detections or process events. The course guide explains that Linux sensors in RFM do not have detections or process events but continue to send heartbeat status. Therefore, the correct answer is that event and detection processing stop, while basic status continues.
CCFA-200b Exam Question 3
What happens to policy assignment when a host does not match any custom host group criteria?
Correct Answer: B
When a host does not match a custom host group assigned to a policy, Falcon applies the applicable Default Policy . Falcon policies operate through host group assignment and precedence. A host may match one or more groups; when multiple policies apply, precedence determines which policy wins. If no custom policy assignment applies, the default policy is the fallback. The platform does not leave hosts without policy coverage, nor does it retain a previously active custom policy indefinitely once the host no longer qualifies. It also does not automatically choose the most restrictive policy unless that policy is assigned and has the highest precedence. This default-policy behavior is central to safe policy design in CCFA: administrators must review default policy settings because unassigned hosts inherit them.
CCFA-200b Exam Question 4
What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?
Correct Answer: B
The correct page is Sensor Health . The Sensor Health dashboard is designed to show Falcon sensor operational status across the environment and help administrators identify hosts running unsupported sensor versions, unsupported operating system versions, incorrect configurations, connectivity problems, and RFM conditions. The official guidance states that the Sensor Health dashboard includes information about "hosts that entered RFM each day" and clarifies that this shows hosts newly entering Reduced Functionality Mode, not the total number of hosts currently in RFM. This distinction matters because Sensor Health is used to track newly emerging sensor health issues over time, while Host Management can be used to filter for the current list of hosts in RFM. Hosts Overview and Activity Overview do not provide this specific daily RFM count. Support and resources is a navigation area, not the sensor health reporting dashboard. Reference topics: Dashboards and Reports, Sensor Health Dashboard, Reduced Functionality Mode, Sensor Operational Status.
CCFA-200b Exam Question 5
What information can be found in the Real Time Response (RTR) Audit Log?
Correct Answer: C
The Real Time Response audit log records operational details about RTR sessions, including who connected, which host was accessed, when the session began, how long it lasted, which commands were run, and files retrieved through RTR activity. The course guidance describes the RTR sessions audit log as a history of recorded activity for the CID's Real Time Response sessions. It includes session start time, session status, user, hostname, connected-from source, commands used, and session duration. Session details also include host details, retrieved files, and detections, with command history subject to specific exclusions such as help, clear, and history, which are not recorded. Option A describes host inventory and policy context rather than RTR session auditing. Option B is incomplete and emphasizes command return results, which is not the core listed audit-log summary. Option D is incorrect because RTR activity is explicitly collected in audit logs. CCFA reference topics: Real Time Response, RTR Audit Logs, Session Details, Host Management and Setup.