Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 6Objective 2

6.2 Interpret Business Requirements in Order to Allow Trusted Activity, Resolve False Positives and Fix Performance Issues CCFA Practice Questions (Page 2)

Part of the Rules Configuration domain, which makes up ~13% of our current practice bank.

14questions here
3free pages
4concepts

Questions 6–10

  1. 6application · medium

    A logistics company reports that Falcon is causing noticeable latency on servers running a custom inventory management system. The system frequently opens and closes many short-lived network connections to a central database. The security team has confirmed this is normal behavior for the application. The administrator needs to reduce the performance impact while still detecting unusual network activity from other processes. What should the administrator do?

    Select an answer first
  2. 7expert · hard · select all that apply

    A large organization is experiencing performance issues on endpoints running a legacy enterprise resource planning (ERP) application. The application performs frequent, legitimate registry reads and writes to a specific set of registry keys. Falcon is causing noticeable CPU overhead on these endpoints. The security team wants to reduce the performance impact without weakening detection for other registry activity. Which two actions should the administrator take? (Select all that apply.)

    Select an answer first
  3. 8foundation · easy

    A Falcon rule is causing latency on endpoints because it performs deep inspection on every file operation. Which configuration change is most likely to reduce latency while keeping the rule effective?

    Select an answer first
  4. 9application · medium

    A hospital's IT team reports that Falcon is alerting on a custom electronic medical records (EMR) application. The application routinely opens a network socket to a local database server and writes temporary files to a shared directory. These actions are required for the application to function. The security team confirms the behavior is benign and wants to stop the alerts without weakening detection for other processes. What should the administrator do?

    Select an answer first
  5. 10foundation · easy

    A server is experiencing high CPU usage due to Falcon's scanning of a large directory that changes frequently. Which rule configuration change is most likely to reduce the performance impact?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.