What best describes the relationship between Sensor Update policies and Operating Systems?
Correct Answer: A
Sensor Update policies are platform-specific, meaning separate policies exist for Windows, Mac, and Linux sensors. The official Sensor Update Policies guidance states that administrators use these policies to control the update process for sensors on hosts, and that each host is assigned to a sensor policy based on host group membership. It then specifies that there are separate sensor update policies for separate platforms: Windows, Mac, and Linux. Therefore, a single sensor update policy cannot be universally applied across all operating systems. Windows does not share update policies with macOS, and macOS does not share update policies with Linux. Linux kernel compatibility is an important deployment consideration, but it does not mean Windows and Mac share one policy family while Linux alone has a different model. The correct CCFA principle is that sensor update management is performed per supported platform, then targeted to host groups within that platform. Reference topics: Sensor Deployment, Sensor Update Policies, platform-specific sensor management, host group policy assignment.
CCFA-200b Exam Question 7
Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to "C:\Users\Bob\DevCode\felix.dll". In the detection, you see that it is triggering only on a specific Falcon IOA. What would be the best course of action for this situation?
Correct Answer: A
Because the detection is triggering only on a specific Falcon IOA, the correct remediation is an IOA exclusion scoped to the relevant detection context and file path. IOA exclusions are intended to reduce false-positive behavioral detections and preventions. Falcon guidance states that IOA exclusions "reduce false-positive detection alerts from IOAs" by stopping behavioral IOA detections and preventions, and they can be created directly from a CrowdStrike-generated detection or by duplicating an existing exclusion. A Custom IOC Allow would be appropriate for an indicator-based decision, such as a known-good hash, but this scenario is explicitly behavioral because the trigger is a Falcon IOA. Manually disabling the built-in IOA through prevention policies is too broad and weakens protection beyond the single development artifact. A sensor visibility exclusion would suppress sensor event visibility and is broader than required. CCFA reference topics: Detection and Prevention Policies, IOA Exclusions, Rule Configuration, false-positive handling.
CCFA-200b Exam Question 8
What policy setting should be selected for a new host when it has an existing antivirus?
Correct Answer: C
The correct setting is Moderate Level ML . Falcon's prevention policy guidance recommends Moderate for most use cases, and the staged deployment model for environments with pre-existing antivirus begins with Phase 1, where machine-learning prevention is conservative while detection is used to triage and tune. The important CCFA concept is not to begin with Extra Aggressive or Aggressive prevention on a newly deployed host with another antivirus product, because that increases false-positive and compatibility risk. Cautious detects only when confidence is very high, but Falcon's recommended baseline for practical protection is Moderate. The course guide states that Moderate detects or prevents when the machine-learning system has moderate confidence and is recommended for most use cases, while Extra Aggressive is not recommended outside penetration testing scenarios.
CCFA-200b Exam Question 9
You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?
Correct Answer: B
Red Hat Enterprise Linux is an operating system distribution and version family, so the most precise Host Management filter is OS version . Platform would generally distinguish broad operating system families such as Windows, macOS, or Linux, but it would not narrow results specifically to RHEL. Type identifies host form factor or role, such as desktop, server, or domain controller. OU refers to Active Directory organizational unit membership, which applies to directory-joined assets rather than Linux distribution identity. The course guide's Host Management and dynamic grouping filter list identifies OS Version as the field used for the installed operating system version. Therefore, to locate RHEL systems, OS version is the most appropriate filter.
CCFA-200b Exam Question 10
Which report would show you an overview of the top ten most-applied policies by sensors in your environment?
Correct Answer: B
The Sensor report dashboard is the best answer because it provides an overview of active sensors in the environment and summarizes deployment and coverage data for sensor administration. The question asks for an overview of the top ten most-applied policies by sensors, which is a dashboard-level summary rather than a per-host assignment lookup. The Sensor Policy Daily Report is more granular: it is used to review the groups and policies assigned to a host and is updated once per day, so it is not the best choice for a top-ten environmental overview. Scheduled reports are a delivery mechanism for recurring report generation, not the specific report containing the requested sensor-policy overview. Executive Summary provides broader executive-level security posture information and is not the focused sensor-policy distribution view. CCFA reporting guidance places sensor deployment and coverage reporting under Sensors, where the Sensor Report provides the overview of active sensors and related sensor-management posture. Reference topics: Dashboards and Reports, Sensors reports, Sensor Report dashboard, Sensor Policy Daily Report.