Browse all practice questions for the CrowdStrike Certified Falcon Administrator (CCFA) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CrowdStrike Certified Falcon Administrator (CCFA) Practice Test – Prep & Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What command should be used to set new grouping tags on a Mac for Falcon?
  • Hunting Reports in CrowdStrike mainly provide information regarding?
  • What is a limitation of a Falcon Security Lead regarding user management?
  • What is required to add IOCs from the Detections page?
  • What effect does RFM have on a Windows sensor immediately after an update?
  • What key must be configured for Sensor Deployment on Windows OS?
  • What does disabling detections prevent in the Falcon UI?
  • Which roles can view exclusions and exclusion audit logs?
  • Where do you initially navigate to create a containment policy?
  • To install the Falcon sensor using the 'Pay as you go' billing type, which parameters are needed?
  • What can be used to view the number of sensors in RFM across various reports?
  • What type of actions are tracked in the API Audit Trail?
  • What is the recommended installation method for Falcon on a Mac?
  • What capability does the Endpoint Manager role have in Prevent Roles?
  • What functionality is restricted for a Workflow Author role?
  • Which of the following is correct regarding file pattern exclusions for different operating systems?
  • Which of the following best describes the function of Linux sensors in RFM?
  • In which scenario is it best to disable updates?
  • What does a value of 2 in the SensorHeartbeat event indicate for a host?
  • What does the acronym AID stand for in relation to Falcon agents?
  • Which type of hash is not recommended due to hash collisions?
  • When installing the Falcon sensor in a virtual environment, which parameter should be included?
  • Which setting would you choose to ensure a suspicious file is prevented from executing but not shown in detections?
  • What information does the Falcon UI Audit Trail Report provide?
  • How can hosts be assigned to a dynamic host group?
  • Which recommendation is suggested for the default policy in sensor update management?
  • What function does Sensor Visibility serve in policy settings?
  • Which action should be performed after selecting "Delete User" in the Falcon console?
  • Which user role can reset users' credentials and manage detections?
  • What syntax is used for defining patterns in ML exclusions?
  • Which role can re-execute failed workflows?
  • Which of the following items would you expect to find in a Linux sensor report?
  • What notification is shown to users when the Falcon sensor performs a blocking action?
  • What happens to the default policy in terms of precedence?
  • When installing Falcon on Windows, what do the tags in the command represent?
  • Which role has the ability to create and manage machine learning exclusions?
  • Which role has access to create, edit, and delete host groups?
  • What is the primary recommendation for implementing Prevention Policies for new customers?
  • Which command can verify if the sensor is connected to the CrowdStrike cloud?
  • What do ML exclusions prevent apart from stopping file uploads to the CrowdStrike cloud?
  • During the installation process, what must be accepted to proceed with Falcon installation?
  • What can a Falcon Administrator do in terms of user management?
  • What permissions does a Prevention Policy Manager have?
  • What happens to events when IOA exclusions are applied?
  • What happens if Single Sign-On (SSO) is not enabled in an environment?
  • How long are quarantined files retained in the CrowdStrike cloud?
  • In the context of exclusion rules, what does the syntax '*' represent?
  • What is the function of glob syntax in creating file exclusion rules?
  • What can you do if you need a longer EAM retention period than the default of 7 days?
  • What happens to quarantined files once they are released?
  • What is the required value for the registry key in Windows OS sensor deployment?
  • Which command is used to uninstall a sensor on a Windows offline host?
  • In Reduced Functionality Mode (RFM), what can the Falcon sensor only send?
  • What happens if the sensor cannot connect to CrowdStrike cloud during installation after multiple attempts?
  • What happens to new detections after a host is deleted in the system?
  • Active connection data from which command indicates the sensor's connection to CrowdStrike cloud?
  • Which command can be added to the installation command to prevent the Falcon sensor from making any proxy connections?
  • Which feature helps in grouping tags assigned to a host?
  • Where can you apply filters to show hosts in Reduced Functionality Mode (RFM)?
  • Which of the following is NOT a primary filter available in the Host Management section?
  • What kind of command line activity can be monitored in the Hunting Reports?
  • Which cloud behavior indicates the sensor is installed on the host during RFM?
  • What is the primary purpose of the Auto-Complete feature in the filter bar?
  • For what purpose are Sensor Visibility Exclusions (SVE) typically used?
  • Which action shows a detection as blocked but is not available in detections?
  • How are hosts in CrowdStrike Falcon typically grouped?
  • Which type of exclusions stop behavioral detections based on command line usage?
  • What type of host group allows the use of filters to define its members?
  • What information must you specify in the installation command for the Falcon sensor on Windows regarding the proxy?
  • In what format does the Remote Access Graph show connections?
  • How can you uninstall the sensor on a Mac system?
  • Which role is NOT able to edit custom workflows in Falcon?
  • What action is triggered if a process matches a custom IOA rule?
  • Which action is unnecessary when creating new exclusions in CrowdStrike?
  • What is a recommended practice when creating groups in CrowdStrike?
  • Which role is required to create and edit IOC management settings?
  • What does the auto-update setting "Auto N-1" do?
  • What is a crucial requirement for sensor deployment regarding network connectivity?
  • How can you view the current sensor grouping tags on a Mac?
  • What parameter is used to assign tags to a host during installation?
  • What command is used to assign tags to a host in CrowdStrike?
  • What does the process of restoring a host from Trash accomplish?
  • What type of data does the Logon Activity Report aggregate?
  • When troubleshooting connectivity on a Windows OS, which command is used to confirm connectivity with the Falcon cloud?
  • Which of the following is NOT a rule type for IOA on Windows?
  • Which temporary location is used if the Falcon sensor installation is initiated by the CrowdStrike cloud?
  • What characterizes Phase 1 of the Prevention Policy implementation?
  • What does the 'NO_START=1' command do during the Falcon installation on a VM?
  • What is the potential role of a response and containment policy?
  • In the context of policy application, what does dynamic group assignment mean?
  • What do custom IOA rules monitor?
  • What type of information can the Falcon Analyst read concerning firewall?
  • What must be confirmed when disabling detections for a host?
  • What is the primary function of the Quarantine Manager?
  • Which role is responsible for managing custom IOCs and exclusions?
  • What type of environments are static host groups particularly useful for?
  • What is the intended outcome of applying file pattern exclusions to groups?
  • Which report detail would help identify spawning shells?
  • What is the purpose of the Linux Sensors Report in relation to host reporting?
  • Which group is recommended for testing updates on a limited number of non-production hosts?
  • What happens to quarantined files after 90 days in CrowdStrike?
  • What is the primary function of Malware Protection in CrowdStrike's policy settings?
  • What should be used if a host requires more provisioning time during sensor installation?
  • Which actions can be taken to contain a host?
  • What is the default wait time set for sensor installation if timing out?
  • What happens when a host is moved to a policy with no updates selected?
  • After uninstalling a sensor on Windows, which folder should no longer exist?
  • What action can you take to modify a user's first and last name?
  • Where can the sensor update policies be managed?
  • Which task can only be performed by an RTR Admin?
  • What is the purpose of ML exclusions?
  • What is the purpose of the cloud connection site 'cloudsink.net'?
  • What should be done during Phase 2 of the Prevention Policy implementation?
  • What happens if TLS 1.2 is disabled on a Windows machine using Falcon?
  • What is the purpose of utilizing commands like "encrypt" in RTR?
  • What additional capability does the RTR Active Responder possess that the RTR Read Only Analyst does not?
  • What kind of detections does an IOA exclusion stop?
  • Who can create, edit, manage, and delete dashboards?
  • How many tags can be added to a single host in the Falcon platform?
  • Which of the following statements is true about the On-Cloud Machine Learning?
  • What requirements must be met for Sensor Deployment on Linux OS?
  • How are ML exclusions created?
  • What type of actions cannot be included by a Workflow Author without an additional role?
  • Which service is specifically mentioned for sending notifications through custom workflows?
  • What does precedence ensure in sensor update policies?
  • Which of the following best describes the role of prevention policies in CrowdStrike?
  • What does the GLOB SYNTAX in exclusions help define?
  • How can you check the number of devices in RFM?
  • In a containment policy, whom can change the containment status?
  • What time frame applies to EAM retention for CrowdStrike data?
  • What type of hosts can be contained using the containment policy?
  • What is a key feature of Cloud ML in NextGen AV settings?
  • Which policy setting is responsible for determining the action on unknown executables?
  • Which role is required to create custom IOA rules?
  • Force Address Space Layout Randomization (ASLR) bypass prevention is classified as?
  • To uninstall a sensor on Linux, which command would you use for Ubuntu?
  • What is the first step in deleting a user from the Falcon console?
  • Which of the following is supported as an IOC for Windows, Mac, and Linux?
  • Which feature must be disabled to prevent man-in-the-middle attacks during sensor installation?
  • What command line argument is used to install the Falcon sensor on Windows without any prompts or UI elements?
  • Which user role can view the workflows but cannot create or edit them?
  • How can Mac sensor tags be managed?
  • What is the initial step to uninstall a sensor on a Windows online host?
  • What is the primary function of custom alerts in Falcon?
  • What is the log file location for Sensor Deployment on Windows OS?
  • What is the primary purpose of IOA exclusions in CrowdStrike?
  • Which job role allows the management of quarantined files in Prevent Roles?
  • Which of the following actions can be triggered by custom workflows?
  • What are the two types of host groups within the Falcon platform?
  • Which action should be performed to resolve communication issues with CrowdStrike endpoints?
  • Which service is NOT required for Sensor Deployment on Windows OS?
  • Which of the following is a guideline when creating Sensor Visibility Exclusions?
  • What is the character limit for Falcon Grouping Tags?
  • Which parameter is used for IE proxy detection when installing the Falcon sensor from the command line?
  • What is the first step to install Falcon on Windows using the GUI?
  • What does the global containment policy control?
  • Which tool can be downloaded to aid in uninstalling a sensor on a Windows online host?
  • What command can be used to check if the Falcon agent is running on a Windows system?
  • How long do inactive sensors remain retained before being removed from the UI?
  • What does the Dashboard Admin role require to access the Falcon Console?
  • What is recommended for all operating systems in Phase 3 of the Prevention Policy?
  • What is a key component of the containment policy?
  • Which function is NOT allowed for the RTR Active Responder role?
  • What does the Hunting Reports section in Reporting provide?
  • Which of the following actions is NOT included in a Linux sensor report?
  • What is a unique capability of the RTR Administrator role?
  • Which of the following is true about the containment policy?
  • Where can you find inactive sensors in the CrowdStrike console?
  • What happens to sensor grouping tags when they are removed from all hosts?
  • Which error code refers to a communications problem between CrowdStrike Cloud and the host?
  • What specific type of data does the Preventions Policy Debug Report verify?
  • How can a sensor be reverted to a previous version?
  • After how many days are detections removed from CrowdStrike?
  • How are Falcon grouping tags added to a host?
  • What can users find in the Unique Host Connecting to Countries Map?
  • What does the command 'CsUninstallTool.exe /quiet' accomplish?
  • What type of information can you expect to find in the Prevention Hashes Ignored Report?
  • Which Real Time Responder role can run all commands that the RTR Read Only Analyst can and extract files?
  • In RTR roles, which role is synonymous with having no rights?
  • How long do tags persist if all associated hosts are inactive?
  • What is one of the prerequisites for installing Falcon on a Mac?
  • What information can be gathered using the command 'uname -r' on Linux?
  • What is the significance of 'precedence' in prevention policies?
  • What is the effect on the DetectionSummaryEvent when detections are disabled for a host?
  • Who is responsible for managing host groups and firewall rules?
  • Which role can assign firewall rule groups to firewall policies?
  • What capability is included in both On-Sensor and On-Cloud Machine Learning?
  • What is the main responsibility of a Falcon Analyst in Prevent Roles?
  • Which investigation method would you use to search for specific hosts?
  • What type of notification can you send using custom workflows to inform users?
  • Which command argument should be included when installing Falcon for Virtual Desktop Infrastructure (VDI)?
  • In sensor update policies, what does 'uninstall protection' prevent?
  • To install the Falcon sensor quietly without restarting, which option should be used in the command?
  • Which of the following is a necessary action if network configurations interfere with certificate validation?
  • What limitation does the RTR Read Only Analyst have compared to other roles?
  • Which operating system does NOT have Reduced Functionality Mode (RFM)?
  • What determines a user account's permissions in the Falcon console?
  • What can an Endpoint Manager do?
  • What remains in Event Search after disabling detections for a host?
  • In terms of roles, what does the term "prevent roles" refer to?
  • What must be true about the email address when enabling Single Sign-On?
  • When using exclusion patterns, what should you ensure about paths that include spaces?
  • Which user role has the ability to execute the "encrypt" command in CrowdStrike?
  • What can Falcon Security Leads manage?
  • What type of actions can response policies permit during RTR sessions?
  • The Remote or Network Logon Activity Report focuses on which type of login?
  • What is the purpose of using the '/norestart' command in the Falcon installation on Windows?
  • The Prevention Policy Audit Trail details changes made to which of the following?
  • What is a potential consequence of unauthorized API secret exposure?
  • What type of tags are only added when adding sensors in the Falcon platform?
  • In NextGen AV Settings, which option is categorized as 'Extra Aggressive'?
  • What does the RFC in "RTR" stand for in the context of CrowdStrike?
  • What is the main function of sensor update policies in CrowdStrike?
  • What does the term "precedence" refer to in policy management in CrowdStrike?
  • Which feature allows for the dynamic assignment of hosts to groups based on custom keywords?
  • What capability is reserved for the Falcon Administrator role?
  • What is one of the primary actions of the behavior-based prevention setting?
  • What purpose does adding known benign files to an allowlist serve?
  • Which of the following actions allows the indicator to be saved but takes no action?
  • What information does the Logon Activity Report provide about failed login attempts?
  • What key feature must be enabled in all working update policies?
  • What mode does the Falcon sensor operate in if installed on an unsupported kernel version?
  • Which deployment strategy updates sensors to the newest versions as released?
  • What is one method to uninstall the Falcon sensor on Windows?
  • Which role allows a user to view detections and manage host management?
  • What is the maximum number of hosts you can add to a static host group at one time?
  • What is the recommended setting for Next Gen AV to enable quarantine on files?
  • What does 'Sensor Update Policies' control?
  • When creating IOA exclusions, which type of detection cannot be excluded?
  • What happens to the detections for a host when detections are disabled in the Falcon console?
  • How long are quarantined files kept on the host before deletion?
  • What happens when detections are disabled for a host?
  • What is the maximum number of hosts that can be added to a static host group at a time?
  • What information is needed to add IOCs to the management system?
  • Which registry key should be checked to confirm the DNS cache is correctly set up for the CrowdStrike agent?
  • Which version of TLS must be enabled for Falcon on commercial cloud clients?
  • What command can you use to load the Falcon sensor after updating its grouping tags on a Mac?
  • Which parameter is used to ensure the Falcon sensor installation occurs without immediate launch?
  • In the context of alerts, what does RFM stand for?
  • Which report provides a general overview of a host's status?
  • What action can the Falcon Analyst perform regarding quarantined files?
  • What must be verified when checking **SSL/TLS settings** for proper CrowdStrike functionality?
  • What must be running for Web Proxy Automatic Discovery (WPAD) to work during Sensor Deployment?
  • What occurs to hosts that are deleted in CrowdStrike Falcon?
  • Where can you view build versions for a single sensor?
  • How are prevention policy settings typically determined?
  • Which type of hash is recommended for addition to custom IOCs to avoid issues?
  • What can a Falcon Administrator do in the Falcon Console?
  • What does the Sensor Capabilities setting influence?
  • What action does the "encrypt" command perform in the RTR context?
  • Who can reset another user's password in the Falcon system?
  • What is the significance of the Customer Checksum ID (CCID) in Falcon?
  • After deleting a user, what can also be accessed to remove the user?
  • The Remote Access Graph provides what type of visualization?
  • Which role can view dashboards and manage sensor update policies?
  • Which statement describes the Real Time Responder (RTR) "fake" role?
  • What type of roles can the Falcon Administrator assign to users?
  • What is one of the default configurations of the Default Policy?
  • In the context of preparing a VM for cloning, what must you do AFTER installing the Falcon sensor?
  • What does the Machine-Learning Prevention Monitoring Report show?
  • What data does the Mac Sensor Report provide regarding suspicious activity?
  • What command would you use to verify if the Falcon sensor is running on a Windows host?
  • To add a new user in the Falcon console, which steps should be followed?
  • In sensor update policies, which two operating systems share the same settings?
  • What type of information is provided in the Linux Sensors report?
  • What is the recommended approach for grouping hosts in most cases?
  • Which role in Prevent Roles allows viewing and managing remediation actions?
  • What key component is included in a Linux sensor report?
  • How does containment impact a host's connectivity to the CrowdStrike cloud?
  • What is the default update rate for sensor updates?
  • How are prevention policies configured in CrowdStrike?
  • What is the character limit for a Falcon grouping tag?
  • Which task can the Falcon Administrator NOT do by default?
  • What is a key characteristic of Sensor Visibility Exclusion (SVE)?
  • Which statement correctly describes the Reduced Functionality Mode (RFM) for Windows?
  • Which role is responsible for creating and editing workflows?
  • What must be done to use quarantine on Windows Server 2016 and 2019?
  • What is the minimum operating system requirement for deploying sensors on Android devices?
  • Which report is essential for checking suspicious activities on Mac hosts?
  • Where are sensor install logs located if the installation is initiated by a user?
  • Which of the following areas does Behavior-Based Prevention cover?
  • What is the main scenario where reduced functionality mode (RFM) is most commonly encountered?
  • What does RFM signify in the context of host management?
  • To minimize false positives for required applications, what can be created?
  • What key infrastructure is necessary for the CrowdStrike sensor to operate successfully in a proxy environment?
  • Which of the following is NOT a feature of sensor update policies?
  • What is a best practice for configuring default policies?
  • What are the responsibilities of a Desktop Support Analyst?
  • When deploying sensors on hosts using proxies, which protocol is important to enable?
  • What should you do if certificate pinning or SSL inspection cannot be disabled while using CrowdStrike?
  • What is the default policy in CrowdStrike primarily used for?
  • What does SVE primarily aim to protect against?
  • What is the minimum version requirement for sensor deployment on iOS devices?
  • What access does a Falcon Analyst have in relation to host management?
  • What happens to the API information if the secret is compromised?
  • What is the purpose of a sensor update policy?
  • Which of the following is a requirement for Falcon to be supported on a server?
  • Which URL relates to the US-2 CrowdStrike deployment?
  • Which report would help identify unusual activity related to scheduled tasks?
  • Which command is used to execute the installation of Falcon on a Mac via command line?
  • What specific elements are included in the Visibility Reports?
  • What is a key function of the Firewall Manager?
  • What role does the Falcon Security Lead have regarding user password management?
  • What command is used to find the RFM state from the command line in Linux?
  • What key details does the Prevention Policy Debug Report display?
  • Which location is designated for quarantined files on Windows?
  • What is the main function of a containment policy in CrowdStrike?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy