
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 5Objective 3
5.3 Apply Roles and Policy Settings, and Track and Review Falcon RTR Audit Logs in Order to Manage User Activity CCFA Practice Questions (Page 3)
Part of the Policy Application domain, which makes up ~17% of our current practice bank.
21questions here
5free pages
4concepts
Questions 11–15
- 11
A Falcon administrator is reviewing RTR audit logs and notices a user executed a command to delete a critical system file on multiple hosts. What is the administrator's primary responsibility in this situation?
Select an answer first - 12
What is the primary purpose of assigning a Falcon role to a user?
Select an answer first - 13
A Falcon administrator wants to enforce a security control that prevents unauthorized USB devices from being used on all Windows hosts in the environment. Which Falcon feature should the administrator configure?
Select an answer first - 14
A Falcon administrator needs to grant a new incident responder the ability to initiate Real-time Response (RTR) sessions on Windows hosts, but must prevent the responder from permanently deleting files or modifying registry keys. Which approach should the administrator take?
Select an answer first - 15
An administrator is reviewing RTR audit logs and notices that a user with a role that allows only 'get' and 'put' commands executed a 'runscript' command. The audit log shows the command was successful. The administrator needs to determine if this was a policy violation. What should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.