Crowdstrike

CCFA practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 225-question bank.

Provider
Crowdstrike
Question bank
225
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CCFA, a certification listed under Crowdstrike. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Crowdstrike. The certification credential is issued by Crowdstrike, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    What is the function of a single asterisk (*) in an ML exclusion pattern?

    Choose one answer.

    • The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path
    • The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path
    • The single asterisk is the insertion point for the variable list that follows the path
    • The single asterisk is only used to start an expression, and it represents the drive letter
  2. Question 2 · 1

    One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?

    Choose one answer.

    • USB Device Policy
    • Firewall Rule Group
    • Containment Policy
    • Machine Learning Exclusions
  3. Question 3 · 1

    When a host belongs to more than one host group, how is sensor update precedence determined?

    Choose one answer.

    • Groups have no impact on sensor update policies
    • Sensors of hosts that belong to more than one group must be manually updated
    • The highest precedence policy from the most important group is applied to the host
    • All of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host
  4. Question 4 · 1

    What may prevent a user from logging into Falcon via single sign-on (SSO)?

    Choose one answer.

    • The SSO username doesn't match their email address in Falcon
    • The maintenance token has expired
    • Falcon is in reduced functionality mode
    • The user never configured their security questions
  5. Question 5 · 1

    The Customer ID (CID) is important in which of the following scenarios?

    Choose one answer.

    • When adding a user to the Falcon console under the Users application
    • When performing the sensor installation process
    • When setting up API keys
    • When performing a Host Search
  6. Question 6 · 1

    Which statement describes what is recommended for the Default Sensor Update policy?

    Choose one answer.

    • The Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible
    • The Default Sensor Update should be configured to always automatically upgrade to the latest sensor version
    • Since the Default Sensor Update policy is pre-configured with recommend settings out of the box, configuration of the Default Sensor Update policy is not required
    • No configuration is required. Once a Custom Sensor Update policy is created the Default Sensor Update policy is disabled
  7. Question 7 · 1

    You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?

    Choose one answer.

    • Script-based Execution Monitoring
    • Interpreter-Only
    • Additional User Mode Data
    • Engine (Full Visibility)
  8. Question 8 · 1

    What is the purpose of the Machine-Learning Prevention Monitoring Report?

    Choose one answer.

    • It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
    • It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious
    • It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
    • It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
  9. Question 9 · 1

    The Remote Access Graph in Visibility Reports displays:

    Choose one answer.

    • a bar chart where a bar represents a daily count of remote connections
    • a geographical chart showing the geo-location of remote IP address
    • a graph showing connections between hosts and users
    • a pie chart showing a count per remote logon type
  10. Question 10 · 1

    What internet domain needs to be added to any required allowlists to allow sensors to communicate with the CrowdStrike Cloud?

    Choose one answer.

    • falconcloud.net
    • cloudprotect-cs.net
    • cloudsink.net
    • csfalcon.net
  11. Question 11 · 1

    Why would you use the Prevention Policy Debug Report?

    Choose one answer.

    • To confirm that prevention policy precedence was applied to hosts
    • To confirm the number of detections on a host
    • To confirm that prevention policy settings were applied to a host
    • To confirm the number of host groups to which a policy was applied
  12. Question 12 · 1

    What is the earliest version of Windows Server that a Sensor is compatible with?

    Choose one answer.

    • Server 2012
    • Server 2003
    • Server 2008 R2 SP1
    • Server 2008
  13. Question 13 · 1

    How do you disable all detections for a host?

    Choose one answer.

    • Create an exclusion rule and apply it to the machine or group of machines
    • Contact support and provide them with the Agent ID (AID) for the machine and they will put it on the Disabled Hosts list in your Customer ID (CID)
    • You cannot disable all detections on individual hosts as it would put them at risk
    • In Host Management, select the host and then choose the option to Disable Detections
  14. Question 14 · 1

    Which command would tell you if a Falcon Sensor was running on a Windows host?

    Choose one answer.

    • netstat.exe -f
    • cswindiag.exe -status
    • sc.exe query falcon
    • sc.exe query csagent
  15. Question 15 · 1

    After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?

    Choose one answer.

    • Response Policy
    • IP Allowlist Management
    • Maintenance Token
    • Containment Policy

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free