Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 6Objective 2

6.2 Interpret Business Requirements in Order to Allow Trusted Activity, Resolve False Positives and Fix Performance Issues CCFA Practice Questions (Page 1)

Part of the Rules Configuration domain, which makes up ~13% of our current practice bank.

14questions here
3free pages
4concepts

Questions 1–5

  1. 1foundation · easy

    A customer requires that all Falcon detections for a specific business application be automatically allowed without generating alerts, but only for that application. Which rule configuration action is most appropriate?

    Select an answer first
  2. 2foundation · easy

    A detection rule is generating false positives for a legitimate administrative tool. The administrator wants to reduce these alerts without losing the ability to detect malicious use of similar tools. Which configuration is most appropriate?

    Select an answer first
  3. 3application · medium

    A retail company's security team receives a business requirement from the compliance department: the company must ensure that a specific legacy point-of-sale (POS) application is not disrupted by Falcon detections. The POS application is known to perform unusual file operations that are required for its functionality. The security team wants to maintain detection for other applications. What should the administrator do?

    Select an answer first
  4. 4foundation · easy

    A security team wants to allow a known internal tool to execute without being flagged by Falcon, while still monitoring other activities on the host. Which configuration is appropriate?

    Select an answer first
  5. 5application · medium

    A marketing agency uses a third-party SaaS tool that installs a browser extension and a background service on employee workstations. The service periodically downloads updates from a known vendor URL and writes to a specific temp folder. The security team has verified the vendor's digital signature and wants to allow this activity without generating alerts, but they still want to detect if the same techniques are used by unknown software. What should the administrator do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.