Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 5Objective 3

5.3 Apply Roles and Policy Settings, and Track and Review Falcon RTR Audit Logs in Order to Manage User Activity CCFA Practice Questions (Page 1)

Part of the Policy Application domain, which makes up ~17% of our current practice bank.

21questions here
5free pages
4concepts

Questions 1–5

  1. 1application · medium

    An administrator needs to produce a report of all RTR sessions initiated in the last 30 days, including the user, host, and command executed. The administrator wants to export this data for compliance review. What is the most efficient way to accomplish this?

    Select an answer first
  2. 2expert · hard

    A company has a policy that requires all RTR sessions on production hosts to be initiated only by users with a specific role, and all RTR commands must be logged. The company also wants to ensure that RTR is not available on non-production hosts. How should the administrator configure this?

    Select an answer first
  3. 3expert · hard

    A Falcon administrator is reviewing RTR audit logs and discovers that a user with a custom role that includes 'RTR Active Responder' permissions executed a 'rm -rf' command on a Linux host. The role was intended to allow only read-only commands. The administrator needs to prevent this from happening again while minimizing disruption to the user's legitimate duties. What should the administrator do?

    Select an answer first
  4. 4application · medium

    A security analyst suspects that a Falcon user performed an unauthorized RTR command on a critical server last night. The analyst needs to identify the exact command executed and the user account that ran it. Where should the analyst look?

    Select an answer first
  5. 5application · medium

    During an audit log review, an administrator notices that a user with a role that only allows read-only RTR commands executed a 'put' command to upload a file to a host. The audit log shows the command was successful. What should the administrator conclude?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.