Free CCFA-200 Practice Test Questions and Answers (2026)
What's covered in this practice questions set
2: Falcon Host/Sensor Management, · 7 questions
📖 About this Domain
This domain covers the operational management of the CrowdStrike Falcon sensor. It focuses on the deployment, grouping, and policy application for hosts within the Falcon UI. Core concepts include sensor installation, host management, and policy configuration.
🎓 What You Will Learn
- You will learn the procedures for installing the Falcon sensor on Windows, macOS, and Linux operating systems.
- You will learn to create and manage static and dynamic host groups to organize endpoints effectively.
- You will learn how to configure and assign Prevention, Sensor Update, and Response policies to host groups.
- You will learn to use the Host Management application to monitor sensor versions and overall host health.
🛠️ Skills You Will Build
- You will build the skill to deploy and provision the Falcon sensor across an enterprise environment.
- You will build proficiency in applying granular security policies using host groups for targeted enforcement.
- You will develop the ability to manage the sensor update lifecycle through Sensor Update policies.
- You will gain the skill to query and filter hosts within the console to identify specific endpoint states.
💡 Top Tips to Prepare
- Focus on the different methods for sensor installation, including command-line arguments like the CID.
- Understand the distinction and use cases for static versus dynamic host groups.
- Memorize the policy precedence order for Prevention and Sensor Update policies.
- Practice navigating the Host Management app to find specific hosts and their sensor details.
3: Falcon Policies, · 6 questions
📖 About this Domain
This domain focuses on the configuration and management of Falcon policies to control sensor behavior. Policies are the primary mechanism for defining prevention settings, sensor updates, and response actions. Understanding policy structure and assignment is fundamental to administering the Falcon platform.
🎓 What You Will Learn
- Differentiate between policy types, including Prevention, Sensor Update, Response, and Firewall policies.
- Configure specific prevention settings, such as Machine Learning (ML) levels and behavioral-based detections (IOAs).
- Understand the rules of policy precedence and how policies are assigned to Host Groups for enforcement.
- Manage the lifecycle of policies through creation, cloning, and versioning within the Falcon console.
🛠️ Skills You Will Build
- Implement granular security controls by assigning tailored policies to distinct Host Groups.
- Tune the organization's security posture by adjusting prevention levels from Cautious to Aggressive.
- Troubleshoot policy conflicts by analyzing inheritance and determining the effective policy on an endpoint.
- Streamline sensor management across the enterprise by leveraging policy cloning and modification.
💡 Top Tips to Prepare
- Familiarize yourself with the policy editor UI in the Falcon console, noting the location of all key settings.
- Master the concept of policy precedence, as questions will test your understanding of which policy applies based on Host Group hierarchy.
- Know the specific function of each Next-Gen Antivirus (NGAV) and IOA setting within a prevention policy.
- Practice with scenarios involving multiple Host Groups and policies to predict the final applied configuration on a given host.
4: Falcon Detections and Incidents, · 4 questions
📖 About this Domain
This domain covers the core analyst workflow for handling security events within the CrowdStrike Falcon console. It details the process of triaging individual Falcon detections and analyzing correlated incidents. The focus is on the Detections app and the Incident Workbench.
🎓 What You Will Learn
- You will learn to interpret detection details, including the process tree, command-line data, and MITRE ATT&CK framework mappings.
- You will learn the detection management lifecycle, including assigning status, severity, and comments to alerts.
- You will learn how the Falcon platform uses automatic correlation to group related detections into a single incident.
- You will learn to navigate the Incident Workbench to view the complete timeline and scope of a security event.
🛠️ Skills You Will Build
- You will build the skill to perform initial triage on new detections to determine true positives from false positives.
- You will build the skill to scope an attack by pivoting from detection data to related hosts, users, and IOCs.
- You will build the skill to use information from a detection to initiate network containment and other response actions.
- You will build the skill to construct event search queries based on artifacts found within a detection's details.
💡 Top Tips to Prepare
- Master the components of the process tree view, as it is fundamental to understanding detection context.
- Practice filtering and searching within the Detections app to quickly find relevant alerts based on specific criteria.
- Understand the key differences between a detection and an incident and how they relate to each other in the Falcon UI.
- Memorize the definitions for detection statuses like 'New', 'In Progress', and 'True Positive' and when to apply them.
5: Falcon User Management, · 3 questions
📖 About this Domain
This domain covers the administration of user accounts and API clients within the Falcon platform. You will explore role-based access control (RBAC) to manage permissions for users and scripts. Proper user management is critical for maintaining security posture and operational integrity in your Customer Identification (CID).
🎓 What You Will Learn
- Learn to create, modify, and delete user accounts in the Falcon console.
- Understand the different built-in user roles and their associated permissions.
- Discover how to create and manage API clients for programmatic access using OAuth2.
- Grasp the concept of role-based access control (RBAC) to enforce least privilege.
🛠️ Skills You Will Build
- Configure user roles to grant specific permissions for console access.
- Implement API clients with appropriate scopes for automation and integration tasks.
- Audit user activity and manage user sessions for security compliance.
- Troubleshoot access issues related to user permissions and role assignments.
💡 Top Tips to Prepare
- Memorize the key differences between built-in roles like Falcon Administrator, Analyst, and Investigator.
- Practice creating an API client and assigning specific API scopes in a lab environment.
- Understand the process for inviting new users and resetting multi-factor authentication (MFA).
- Review the user management interface in the Falcon console to familiarize yourself with all available options.
1: Falcon Platform,
📖 About this Domain
This domain covers the fundamental architecture of the CrowdStrike Falcon platform. It details the interaction between the Falcon sensor, the cloud-native backend, and the Threat Graph. Navigating the Falcon console and understanding its core applications is a primary focus.
🎓 What You Will Learn
- You will learn the Falcon platform's architecture, including the lightweight sensor, cloud correlation engine, and API integrations.
- You will understand how to navigate the Falcon UI, including the Activity, Investigate, Discover, and Dashboards applications.
- You will learn the process for sensor deployment, host group creation, and policy management.
- You will be introduced to the core capabilities of modules like Falcon Prevent (NGAV) and Falcon Insight (EDR).
🛠️ Skills You Will Build
- You will build the skill to navigate the Falcon console to find specific hosts, detections, and user information.
- You will develop the ability to create, modify, and assign prevention policies and sensor update policies.
- You will gain proficiency in managing hosts by creating static and dynamic host groups using filtering criteria.
- You will learn to interpret data from various dashboards to assess an environment's overall security posture.
💡 Top Tips to Prepare
- Gain hands-on experience by navigating a live or lab Falcon console to build familiarity with the UI.
- Focus on the data flow from the endpoint sensor to the cloud and how events are processed and displayed.
- Memorize the key configuration options within prevention policies and their direct impact on endpoint protection.
- Understand the distinct purpose of each major application, such as using Investigate for searching and Discover for asset inventory.