Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 5Objective 3

5.3 Apply Roles and Policy Settings, and Track and Review Falcon RTR Audit Logs in Order to Manage User Activity CCFA Practice Questions (Page 2)

Part of the Policy Application domain, which makes up ~17% of our current practice bank.

21questions here
5free pages
4concepts

Questions 6–10

  1. 6foundation · easy

    A Falcon administrator needs to review a list of all real-time response sessions that occurred in the last 24 hours, including who initiated them and on which hosts. Where should the administrator look in the Falcon console?

    Select an answer first
  2. 7foundation · easy

    What is the primary purpose of applying a policy setting in Falcon?

    Select an answer first
  3. 8foundation · easy

    What is the primary purpose of reviewing RTR audit logs?

    Select an answer first
  4. 9application · medium

    An administrator is reviewing RTR audit logs and finds multiple failed RTR session attempts from a single user account within a short time frame. The user is a legitimate administrator. What should the administrator do?

    Select an answer first
  5. 10foundation · easy

    A Falcon administrator needs to grant a new security analyst the ability to view host data and run read-only Falcon queries, but not modify any policies or perform response actions. Which Falcon feature should the administrator use to define these permissions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.