
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 3Objective 2
3.2 Disable Detections for a Host CCFA Practice Questions (Page 3)
Part of the Host Management and Setup domain, which makes up ~25% of our current practice bank.
24questions here
5free pages
5concepts
Questions 11–15
- 11
A security manager wants to ensure that no single administrator can permanently disable detections on a host without a second person's approval. Which of the following approaches best addresses this requirement?
Select an answer first - 12
A Falcon administrator disabled detections on a host for a maintenance window. After the window, the administrator re-enabled detections. However, the security team reports that the host is still not appearing in detection reports. Which of the following is the most likely cause?
Select an answer first - 13
A Falcon administrator is looking for a host in the console to disable detections. The administrator knows the host's IP address but not the exact hostname. How can the administrator locate the host?
Select an answer first - 14
A Falcon administrator disables detections on a host to troubleshoot a performance issue. After the troubleshooting is complete, the administrator forgets to re-enable detections. Several days later, a security analyst notices the host is missing from detection reports. What is the most likely reason for this?
Select an answer first - 15
What is the primary purpose of disabling detections for a specific host in CrowdStrike Falcon?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.