Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Administrator (CCFA)

Domain 7Objective 2

7.2 Understand the Different Audit Logs and Their Use Cases CCFA Practice Questions (Page 4)

Part of the Dashboards and Reports domain, which makes up ~5% of our current practice bank.

19questions here
4free pages
4concepts

Questions 16–19

  1. 16foundation · easy

    A security administrator needs to investigate a potential insider threat by reviewing which admin user changed a detection policy last week. Which audit log use case is most appropriate?

    Select an answer first
  2. 17application · medium

    While reviewing an audit log entry, an administrator sees the following fields: 'Timestamp', 'Actor', 'Action', 'Target', and 'Source IP'. What does the 'Actor' field represent?

    Select an answer first
  3. 18application · medium

    An administrator is reviewing an audit log entry and sees the action 'user_role_updated'. What does this action indicate?

    Select an answer first
  4. 19application · medium

    A Falcon administrator needs to provide evidence of a user's login attempts to the Falcon console, including successful and failed attempts. Which audit log should they export?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.