View Full CrowdStrike CCFA Exam Dumps and Practice Test Dumps
Question 61.
A Falcon administrator wants to identify endpoints that have not checked in recently and may no longer be actively protected. What should be reviewed first?
- Host inventory with last-seen and sensor status information
2. Device Control policies
3. Detection comments
4. Dashboard widgets
Correct Answer: 1. Host inventory with last-seen and sensor status information
Explanation:
Host inventory provides the most direct way to identify endpoints that have stopped communicating with Falcon. Reviewing last-seen timestamps, sensor status, operating system information, and other host details can help determine whether systems are offline, stale, or experiencing communication problems. Administrators can then investigate sensor health, local services, proxy configuration, DNS, or firewall connectivity. Device Control and dashboard widgets do not directly indicate whether endpoints are actively reporting. Host communication data should therefore be the first area examined when identifying potentially unprotected systems.
Question 62.
A company wants finance workstations to use stricter prevention settings than standard office endpoints. What should the administrator configure?
- One identical policy for all endpoints
2. Separate prevention policies assigned to appropriate host groups
3. Separate Falcon login pages
4. Different dashboard layouts
Correct Answer: 2. Separate prevention policies assigned to appropriate host groups
Explanation:
Different endpoint populations may have different security requirements based on risk, business function, and operational needs. Creating separate prevention policies allows finance systems to receive stronger controls while standard office endpoints use settings appropriate for their workloads. Host groups provide a scalable way to assign those policies consistently. This approach also supports staged testing before stricter controls are introduced broadly. Dashboard layouts or console login settings do not determine endpoint protection behavior. Policy segmentation is therefore the appropriate administrative design for different endpoint risk profiles.
Question 63.
A Falcon administrator wants Linux servers to be automatically grouped as they are enrolled so they receive server-specific policies. Which feature should be used?
- Detection exclusions
2. Real Time Response
3. Dynamic host groups
4. Custom IOAs
Correct Answer: 3. Dynamic host groups
Explanation:
Dynamic host groups automatically include endpoints that match defined criteria, making them useful for environments where systems are frequently added or changed. The administrator can define criteria that identify Linux servers and then assign the appropriate prevention, sensor update, or other policies to that group. This reduces manual effort and helps maintain consistent security configuration. Real Time Response is intended for investigation and remediation, while Custom IOAs provide behavioral detections. Dynamic grouping is the appropriate feature for automated endpoint organization and policy targeting.
Question 64.
An organization wants to prevent users from writing data to unauthorized removable USB storage. Which Falcon capability should be configured?
- Sensor Update Policy
2. Host containment
3. Firewall Management
4. Device Control**
Correct Answer: 4. Device Control
Explanation:
Device Control is designed to manage the use of removable devices such as USB storage. Administrators can create policies that allow, block, or restrict device activity according to organizational security requirements. This helps reduce the risk of unauthorized data transfer, malware introduction, and information leakage. Host containment addresses compromised systems, while Firewall Management controls network traffic. Sensor update policies manage Falcon sensor versions. Device Control is therefore the appropriate capability when the objective is to govern removable-media access on managed endpoints.
Question 65.
A company wants to validate a new Falcon sensor version on a small set of systems before rolling it out to production. What should be used?
- A dedicated sensor update policy for a pilot host group
2. A global prevention exclusion
3. A custom firewall rule
4. A detection suppression rule
Correct Answer: 1. A dedicated sensor update policy for a pilot host group
Explanation:
A pilot sensor update policy allows administrators to deploy a newer Falcon sensor version to a controlled set of representative endpoints first. This provides time to validate application compatibility, stability, and performance before expanding deployment to production systems. If issues are discovered, the impact remains limited to the pilot group. Detection exclusions and firewall rules do not control sensor version distribution. A staged sensor rollout is a safer operational approach and helps organizations balance rapid adoption of updates with production stability.
Question 66.
A security responder needs to remotely collect information from an endpoint and execute approved investigative commands. Which capability should be used?
- Firewall Management
2. Real Time Response
3. Device Control
4. Sensor Update Policy
Correct Answer: 2. Real Time Response
Explanation:
Real Time Response allows authorized analysts to remotely interact with managed endpoints during investigation and remediation. Depending on assigned permissions, responders can inspect files, processes, system information, and other artifacts and can execute approved response actions. This capability is especially valuable when physical access to the device is unavailable or when rapid investigation is required. Firewall Management and Device Control address different security functions. Because Real Time Response provides powerful remote capabilities, organizations should restrict access through appropriate role-based permissions and oversight.
Question 67.
A large enterprise wants marketing, engineering, and server endpoints to receive different Falcon policies without managing every device individually. What should be used?
- Shared administrator accounts
2. Manual per-host configuration
3. Host groups with policy assignments
4. Detection comments
Correct Answer: 3. Host groups with policy assignments
Explanation:
Host groups allow endpoints to be organized according to business unit, operating system, location, server role, or other useful characteristics. Falcon policies can then be assigned to groups instead of to individual endpoints, making administration more scalable and consistent. Dynamic host groups can further automate membership as systems are added or modified. Manual host-by-host management becomes difficult in large environments and increases the risk of inconsistent settings. Group-based policy assignment is therefore a more efficient and reliable method for managing varied endpoint populations.
Question 68.
A company wants to centrally enforce different firewall rules on servers and user workstations. Which CrowdStrike capability should be used?
- Device Control
2. Real Time Response
3. Custom IOAs
4. Firewall Management**
Correct Answer: 4. Firewall Management
Explanation:
Firewall Management enables centralized administration of supported endpoint firewall rules and policies through Falcon. Administrators can define different network restrictions for server and workstation groups and assign those policies appropriately. This helps maintain consistent inbound and outbound traffic controls across the environment while reducing local configuration drift. Device Control manages removable media, Real Time Response supports remote investigation, and Custom IOAs provide behavior-based detections. Firewall Management is therefore the appropriate feature for centrally governing endpoint firewall behavior.
Question 69.
A security team believes an endpoint is actively compromised and wants to stop most network communication immediately while retaining Falcon access. What should be done?
- Network contain the endpoint
2. Uninstall the Falcon sensor
3. Delete the endpoint record
4. Disable all detections
Correct Answer: 1. Network contain the endpoint
Explanation:
Network containment isolates a suspected endpoint from most normal network communication while preserving the connectivity required for Falcon management and investigation. This can reduce the risk of lateral movement, command-and-control communication, and data exfiltration while responders continue analysis. Removing the sensor would eliminate important visibility and response capabilities, while deleting the endpoint record would not isolate the host. Containment is therefore an effective immediate response when a compromised system must be restricted without losing remote investigative access.
Question 70.
A SOC analyst needs to view detections and host information but should not be able to modify policies or initiate containment. What should be configured?
- Full administrator access
2. A least-privilege role with only required permissions
3. Shared credentials with another analyst
4. Sensor uninstall permissions
Correct Answer: 2. A least-privilege role with only required permissions
Explanation:
Administrative access should be aligned with job responsibilities. A SOC analyst who only needs to review detections and host information should receive a role that provides those capabilities without granting policy modification, containment, or other powerful administrative actions. This follows the principle of least privilege and reduces the possibility of accidental or unauthorized changes. Individual accounts also improve accountability compared with shared credentials. Role-based access control helps organizations maintain separation of duties while still allowing analysts to perform the tasks required for their assigned responsibilities.
Question 71.
A threat hunter wants to determine whether a suspicious IP address has been contacted by multiple endpoints. What should be used?
- Event search or threat hunting capabilities
2. Sensor Update Policy
3. Device Control
4. Dashboard customization
Correct Answer: 1. Event search or threat hunting capabilities
Explanation:
Threat hunting and event-search capabilities allow analysts to query Falcon telemetry for suspicious IP addresses, domains, file hashes, processes, and other indicators. Searching for an IP address can reveal which endpoints communicated with it, when those connections occurred, and what processes were involved. This helps analysts determine incident scope and identify potentially affected systems. Sensor update policies and Device Control manage endpoint configuration rather than historical telemetry. Threat hunting is therefore the appropriate method for investigating suspicious infrastructure across the environment.
Question 72.
A trusted internal utility generates repeated Falcon detections. What should the administrator do before adding an exclusion?
- Disable prevention globally
2. Confirm the utility is legitimate and create the narrowest justified exception
3. Remove Falcon from affected systems
4. Ignore every detection from those hosts
Correct Answer: 2. Confirm the utility is legitimate and create the narrowest justified exception
Explanation:
Exclusions reduce security visibility, so they should be created only after the triggering application has been validated and the behavior is understood. The administrator should determine whether the utility is genuinely trusted and whether an exclusion is necessary. If so, the exception should be limited as narrowly as possible to the relevant process, file, path, behavior, or host population where supported. Broad exclusions or globally disabling prevention could hide unrelated threats. Carefully scoped exceptions preserve protection while resolving legitimate business compatibility problems.
Question 73.
A security engineer wants Falcon to detect a specific command-line behavior associated with an internal attack simulation. Which feature should be considered?
- Sensor update policies
2. Host deletion
3. Custom Indicators of Attack
4. Device Control
Correct Answer: 3. Custom Indicators of Attack
Explanation:
Custom Indicators of Attack allow security teams to define behavior-based detection logic tailored to their environment. They can be useful for detecting suspicious command lines, process relationships, or execution patterns that may not be represented by a simple static indicator. This makes them suitable for organization-specific threat scenarios and security testing. Custom IOAs should be validated carefully to reduce false positives or unnecessary blocking. Sensor update policies and Device Control handle administrative functions rather than custom behavioral detection.
Question 74.
A newly installed Falcon sensor is not appearing in the console. Which area should the administrator investigate first?
- USB policy configuration
2. Dashboard layout
3. Detection severity
4. Sensor installation, cloud connectivity, and customer identifier configuration**
Correct Answer: 4. Sensor installation, cloud connectivity, and customer identifier configuration
Explanation:
A Falcon sensor must be installed correctly, associated with the correct customer environment, and able to communicate with CrowdStrike cloud services before the host can appear properly in the console. The administrator should verify installation success, customer identifier configuration, DNS resolution, proxy settings, firewall access, and general connectivity. Device Control and detection severity do not determine whether a sensor enrolls successfully. Troubleshooting should therefore begin with sensor installation and communication fundamentals before examining unrelated configuration areas.
Question 75.
A Falcon administrator is preparing a significantly more restrictive prevention policy. What is the safest rollout method?
- Apply the policy to a representative pilot group first
2. Deploy it immediately to all endpoints
3. Disable sensor updates
4. Remove all existing policies
Correct Answer: 1. Apply the policy to a representative pilot group first
Explanation:
A representative pilot group provides an opportunity to validate the effects of stricter prevention settings before they are deployed across the organization. Administrators can monitor for false positives, application disruption, performance issues, and unexpected blocking. If the policy performs correctly, deployment can be expanded in stages. Applying a restrictive policy to every endpoint immediately increases the risk of widespread business disruption. A controlled rollout therefore provides a better balance between improving security and maintaining system availability and user productivity.
Question 76.
An endpoint is unexpectedly receiving a policy intended for another business unit. What should the Falcon administrator examine first?
- Local browser history
2. Host-group membership, policy assignment, and precedence
3. Detection comments
4. Screen resolution
Correct Answer: 2. Host-group membership, policy assignment, and precedence
Explanation:
Unexpected policy application often results from group membership or policy precedence. An endpoint may match a dynamic group rule that the administrator did not expect, or it may belong to multiple groups associated with different policies. When several policies are applicable, precedence determines which one becomes effective. Reviewing group membership, targeting, and precedence helps identify why the endpoint received the configuration. Browser history and display settings do not influence Falcon policy assignment. These policy relationships should therefore be investigated first.
Question 77.
A Falcon detection indicates active command-and-control traffic from a workstation. What is the most appropriate immediate containment action?
- Network contain the workstation
2. Delete the detection
3. Uninstall the Falcon sensor
4. Disable endpoint telemetry
Correct Answer: 1. Network contain the workstation
Explanation:
Network containment helps immediately restrict most communication from the suspected workstation, reducing the attacker’s ability to maintain command-and-control access, move laterally, or transfer data. CrowdStrike connectivity needed for investigation and response is preserved, allowing analysts to continue working with the endpoint. Deleting the detection changes only the record and does not stop malicious communication. Uninstalling Falcon or disabling telemetry would reduce security visibility. Containment is therefore the appropriate immediate action when an endpoint is actively communicating with malicious infrastructure.
Question 78.
A company wants critical database servers to remain on a validated Falcon sensor version while ordinary workstations receive newer sensor versions sooner. What should be configured?
- Custom IOAs
2. Separate sensor update policies
3. Device Control exclusions
4. Detection comments
Correct Answer: 2. Separate sensor update policies
Explanation:
Separate sensor update policies allow administrators to control sensor version deployment independently for different endpoint populations. Critical database servers can remain on a tested version while workstations adopt newer versions more quickly. This helps maintain stability on sensitive systems without preventing other endpoints from receiving newer functionality and protections. Host groups can be used to assign the appropriate update policy to each population. Custom IOAs and Device Control settings do not manage Falcon sensor versions, so sensor update policies are the appropriate solution.
Question 79.
A Falcon administrator created a new prevention policy, but several expected endpoints are not receiving it. What should be verified first?
- The dashboard theme
2. The sensor installer filename
3. Host-group membership, policy targeting, and precedence
4. Detection comments
Correct Answer: 3. Host-group membership, policy targeting, and precedence
Explanation:
If a policy is not applying to expected endpoints, administrators should verify that the systems are actually members of the targeted host groups and that the policy assignment is correct. Dynamic group rules may need review if group membership is automatic. When multiple policies could apply, policy precedence should also be checked because another policy may take priority. Dashboard themes and installer filenames do not control effective policy assignment. Reviewing host targeting and precedence is therefore the most direct troubleshooting approach.
Question 80.
Before applying major Falcon policy changes to the entire enterprise, what should the administrator validate?
- Only the policy display name
2. Only the number of endpoints
3. Only dashboard visibility
4. Targeting, precedence, permissions, endpoint impact, and rollback planning**
Correct Answer: 4. Targeting, precedence, permissions, endpoint impact, and rollback planning
Explanation:
Enterprise-wide configuration changes should be validated comprehensively before deployment. The administrator should confirm that the intended host groups are targeted, understand how policy precedence will affect endpoints, and verify that administrative permissions are appropriate. Representative systems should be tested for application compatibility, performance, and operational impact. A rollback or recovery plan should also be prepared in case unexpected problems occur. A phased rollout provides additional protection against widespread disruption. Comprehensive validation helps maintain security while reducing deployment risk.