
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 1Objective 3
1.3 Manage API Keys CCFA Practice Questions (Page 4)
Part of the User Management domain, which makes up ~12% of our current practice bank.
22questions here
5free pages
5concepts
Questions 16–20
- 16
An administrator is creating an API key for a new security orchestration tool that will be used to isolate hosts and retrieve detection details. The tool should not be able to modify prevention policies. What scopes should be assigned to the key?
Select an answer first - 17
What is the immediate effect of revoking an API key in the Falcon console?
Select an answer first - 18
Why is it important to assign API keys the minimum required permissions rather than broad administrative scopes?
Select an answer first - 19
A Falcon administrator notices unusual activity in the audit logs: an API key is making API calls at 3:00 AM, which is outside the normal business hours when the associated integration runs. The calls are failing with permission errors. What should the administrator do first?
Select an answer first - 20
An administrator discovers that an API key used by a former employee's personal script is still active. The employee has left the company, and the script is no longer in use. What is the most immediate and appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.