
CrowdStrikeCertified Falcon Administrator (CCFA)
Domain 5Objective 4
5.4 Understand the Functionality of a Containment Policy CCFA Practice Questions (Page 3)
Part of the Policy Application domain, which makes up ~17% of our current practice bank.
19questions here
4free pages
5concepts
Questions 11–15
- 11
A Falcon administrator is configuring a containment policy for a host group that includes a critical application server. The server cannot be isolated from the network for more than a few minutes without causing a business outage. The administrator wants to ensure that if the server is contained, it is automatically released after a short period. What should the administrator do?
Select an answer first - 12
A Falcon administrator needs to apply a containment policy to a host group that contains both Windows and Linux servers. The policy should isolate hosts from the network on high-severity detections. What should the administrator do?
Select an answer first - 13
In the Falcon console, what type of setting is used to determine which hosts a containment policy applies to?
Select an answer first - 14
A security team wants to ensure that a containment policy is applied to all hosts in the 'Production' host group, but they also want to exclude a specific server that is known to have false positives. What should the administrator do?
Select an answer first - 15
After a containment policy has been applied during an incident, what is a key aspect of monitoring its effectiveness?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFA” is a trademark of its owner, used for identification only.