
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 7Objective 2
7.2 Understand the Different Audit Logs and Their Use Cases CCFA Practice Questions (Page 1)
Part of the Dashboards and Reports domain, which makes up ~5% of our current practice bank.
19questions here
4free pages
4concepts
Questions 1–5
- 1
A Falcon administrator is investigating a security incident and needs to determine if any users attempted to access the Falcon console during a specific time period. Which audit log should they review?
Select an answer first - 2
An administrator needs to access the audit logs to review recent administrative actions. They are currently on the Falcon dashboard. What is the most direct way to access the audit logs?
Select an answer first - 3
A Falcon administrator is investigating a security incident and needs to determine if any API keys were used to access the Falcon API during a specific time window. Which audit log should they consult?
Select an answer first - 4
An administrator is reviewing an audit log entry and sees the 'Source IP' field is '203.0.113.5'. What does this field represent?
Select an answer first - 5
A Falcon administrator is troubleshooting an issue where a user reports they were unable to access a specific file. The administrator wants to check if the user's activity was logged. Which audit log should they check?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.