
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 7Objective 2
7.2 Understand the Different Audit Logs and Their Use Cases CCFA Practice Questions (Page 4)
Part of the Dashboards and Reports domain, which makes up ~5% of our current practice bank.
19questions here
4free pages
4concepts
Questions 16–19
- 16
A security administrator needs to investigate a potential insider threat by reviewing which admin user changed a detection policy last week. Which audit log use case is most appropriate?
Select an answer first - 17
While reviewing an audit log entry, an administrator sees the following fields: 'Timestamp', 'Actor', 'Action', 'Target', and 'Source IP'. What does the 'Actor' field represent?
Select an answer first - 18
An administrator is reviewing an audit log entry and sees the action 'user_role_updated'. What does this action indicate?
Select an answer first - 19
A Falcon administrator needs to provide evidence of a user's login attempts to the Falcon console, including successful and failed attempts. Which audit log should they export?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.