CrowdStrike CCFA Practice Test Questions and Exam Dumps Part5 Q81-100

View Full CrowdStrike CCFA Exam Dumps and Practice Test Dumps

 

Question 81.

A Falcon administrator needs to identify endpoints that have stopped reporting and may no longer be receiving current protection. What should be checked first?

  1. Host inventory, last-seen time, and sensor status
    2. Device Control rules
    3. Dashboard widgets
    4. Detection comments

Correct Answer: 1. Host inventory, last-seen time, and sensor status

Explanation:

Host inventory provides the most direct information about whether managed endpoints are still communicating with the Falcon platform. Reviewing last-seen timestamps and sensor status can help identify stale, offline, or disconnected systems. If a host has stopped checking in, the administrator can then investigate local sensor health, network connectivity, proxy configuration, DNS, or firewall restrictions. Device Control settings and dashboard layout do not indicate whether an endpoint is actively reporting. Host communication data should therefore be the first place to investigate when endpoints appear inactive.

Question 82.

A company wants engineering workstations to use different prevention settings from finance laptops. What should the administrator configure?

  1. One global prevention policy
    2. Separate prevention policies assigned to appropriate host groups
    3. Different dashboard themes
    4. Separate user passwords

Correct Answer: 2. Separate prevention policies assigned to appropriate host groups

Explanation:

Different business units may require different prevention settings because their applications, workflows, and risk profiles are not identical. Separate prevention policies allow administrators to tailor endpoint protections and assign them to appropriate host groups. This approach provides flexibility while keeping policy management centralized and scalable. It also allows changes to be tested on one population before being applied elsewhere. A single global policy may be too restrictive for some users or insufficient for others. Group-based policy assignment is therefore the preferred design for differentiated endpoint protection.

Question 83.

An administrator wants newly enrolled servers that match defined criteria to automatically receive server-specific Falcon policies. Which feature should be used?

  1. Detection exclusions
    2. Real Time Response
    3. Dynamic host groups
    4. Dashboard filters

Correct Answer: 3. Dynamic host groups

Explanation:

Dynamic host groups automatically place endpoints into groups when they match specified criteria. This is useful for environments where new systems are frequently added and should immediately receive the correct prevention, sensor update, firewall, or other policies. The administrator can define rules based on relevant endpoint attributes and allow Falcon to maintain membership automatically. This reduces manual effort and helps prevent configuration drift. Detection exclusions and dashboard filters do not provide automated policy targeting. Dynamic grouping is therefore the appropriate feature for scalable host organization.

Question 84.

A company wants to stop users from connecting unauthorized removable storage devices to corporate laptops. Which Falcon capability should be configured?

  1. Host containment
    2. Firewall Management
    3. Sensor update policy
    4. Device Control**

Correct Answer: 4. Device Control

Explanation:

Device Control allows administrators to manage access to removable storage and supported peripheral devices. Policies can allow, block, or restrict device usage based on organizational requirements. This helps reduce the risk of unauthorized data transfer, malware introduction, and data leakage through removable media. Host containment is used during incident response, Firewall Management controls network traffic, and sensor update policies manage sensor versions. Device Control is therefore the correct capability when the objective is to govern USB and removable-device usage on managed endpoints.

Question 85.

A CrowdStrike administrator wants to validate a new Falcon sensor version on a small number of systems before broad deployment. What should be configured?

  1. A pilot sensor update policy
    2. A global detection exclusion
    3. A dashboard filter
    4. A firewall deny rule

Correct Answer: 1. A pilot sensor update policy

Explanation:

A pilot sensor update policy allows a limited group of representative endpoints to receive a newer Falcon sensor version first. This gives administrators time to verify stability, performance, and application compatibility before the release is deployed more broadly. If an issue appears, the impact is limited to the pilot group rather than the entire environment. Detection exclusions and firewall rules do not control sensor version deployment. A staged sensor update strategy reduces operational risk while still allowing the organization to adopt newer sensor releases in a controlled manner.

Question 86.

A security analyst needs to remotely examine suspicious files and processes on an endpoint. Which Falcon capability should be used?

  1. Device Control
    2. Real Time Response
    3. Sensor Update Policy
    4. Firewall Management

Correct Answer: 2. Real Time Response

Explanation:

Real Time Response allows authorized analysts to interact remotely with managed endpoints during security investigations. Depending on permissions, responders can inspect files, processes, system information, and other artifacts and can perform approved remediation actions. This can significantly speed incident response because analysts do not need physical access to the affected device. Device Control manages removable devices, while sensor update and firewall policies perform different administrative functions. Because Real Time Response is powerful, access should be limited to properly authorized users under least-privilege principles.

Question 87.

A large organization wants different departments to receive different endpoint policies automatically. What is the most scalable approach?

  1. Configure every endpoint individually
    2. Share one administrator account among teams
    3. Use host groups with appropriate policy assignments
    4. Use detection comments to label systems

Correct Answer: 3. Use host groups with appropriate policy assignments

Explanation:

Host groups provide a scalable way to organize endpoints according to business unit, device type, operating system, location, or other relevant characteristics. Policies can then be assigned to those groups so the intended configurations are applied consistently. Dynamic groups can automate membership even further. Managing every host individually increases administrative effort and the risk of inconsistent settings. Shared accounts also reduce accountability. Group-based policy management is therefore the best approach for large environments where different endpoint populations need different Falcon configurations.

Question 88.

A company wants to centrally manage host firewall rules through the Falcon console. Which capability should be used?

  1. Real Time Response
    2. Device Control
    3. Custom IOAs
    4. Firewall Management**

Correct Answer: 4. Firewall Management

Explanation:

Firewall Management allows administrators to centrally define and enforce supported endpoint firewall policies. Different rules can be assigned to different host groups, allowing server, workstation, or specialized endpoint populations to receive appropriate network controls. This helps reduce local configuration drift and simplifies firewall administration across large environments. Device Control governs removable devices, while Real Time Response is used for investigation and remediation. Custom IOAs are used for behavioral detection. Firewall Management is therefore the correct capability for centralized endpoint firewall policy administration.

Question 89.

A workstation is actively communicating with known malicious infrastructure. What should the security team do immediately to reduce risk while retaining Falcon access?

  1. Network contain the workstation
    2. Delete the detection
    3. Remove the Falcon sensor
    4. Disable event collection

Correct Answer: 1. Network contain the workstation

Explanation:

Network containment restricts most communication from a suspicious or compromised endpoint while preserving connectivity needed for CrowdStrike management and response. This can help interrupt command-and-control traffic, lateral movement, or data exfiltration while responders continue investigating. Removing the sensor would reduce visibility and response capability, while deleting a detection only changes the record and does not affect endpoint behavior. Containment is therefore an appropriate immediate action when a system poses an active network threat but must remain available for remote investigation.

Question 90.

A SOC analyst needs to view detections but must not be able to change prevention policies or contain hosts. What should the administrator configure?

  1. Full administrator access
    2. A least-privilege role with only required permissions
    3. Shared administrator credentials
    4. Sensor uninstall privileges

Correct Answer: 2. A least-privilege role with only required permissions

Explanation:

Role-based access should grant users only the capabilities required for their responsibilities. A SOC analyst who needs to review detections can be assigned a role with read or investigation permissions while policy modification and containment privileges remain restricted. This supports least privilege and reduces the risk of accidental or unauthorized actions. Individual user accounts also preserve accountability and auditability. Full administrative access or shared credentials would provide unnecessary capabilities. Proper role design helps security teams safely separate operational responsibilities within the Falcon environment.

Question 91.

A threat hunter wants to determine whether a known malicious file hash has appeared on multiple endpoints. What should be used?

  1. Threat hunting or event search
    2. Device Control
    3. Sensor update policy
    4. Dashboard customization

Correct Answer: 1. Threat hunting or event search

Explanation:

Threat hunting and event search allow analysts to query endpoint telemetry for indicators such as file hashes, process names, domains, and IP addresses. Searching for a known malicious hash can help determine whether the file appeared on additional systems and provide context about related process execution. This is useful for assessing incident scope and identifying potentially affected endpoints. Device Control and sensor update policies handle endpoint configuration rather than telemetry investigation. Threat hunting is therefore the appropriate capability for searching the environment for known indicators.

Question 92.

A trusted internal application repeatedly triggers Falcon prevention actions. What should the administrator do before creating an exclusion?

  1. Disable prevention on all endpoints
    2. Validate the application and create the narrowest justified exception
    3. Remove Falcon from affected systems
    4. Ignore all future detections

Correct Answer: 2. Validate the application and create the narrowest justified exception

Explanation:

Exclusions can reduce protection, so they should be created only after the application is confirmed to be legitimate and the reason for the detection is understood. If an exception is required, it should be scoped as narrowly as possible to the relevant file, path, process, behavior, or host group where supported. Broad exclusions can unintentionally create security gaps and hide unrelated threats. Disabling prevention globally would be excessive. Careful validation and narrow scoping allow administrators to resolve compatibility issues while preserving as much endpoint protection as possible.

Question 93.

A security team wants Falcon to detect a specific suspicious process or command-line behavior unique to its environment. Which feature should be considered?

  1. Sensor update policy
    2. Device Control
    3. Custom Indicators of Attack
    4. Host deletion

Correct Answer: 3. Custom Indicators of Attack

Explanation:

Custom Indicators of Attack allow security teams to define behavior-based detections tailored to their environment. They can be used to identify suspicious process behavior, command-line patterns, or process relationships that may represent malicious activity. This provides more flexibility than relying only on static indicators such as file hashes. Custom IOAs should be tested carefully to reduce false positives and unintended blocking. Sensor update policies and Device Control perform administrative functions rather than creating organization-specific behavioral detections, making Custom IOAs the appropriate feature.

Question 94.

A Falcon sensor has been installed, but the endpoint never appears in the Falcon console. What should the administrator investigate first?

  1. Detection comments
    2. USB policy settings
    3. Dashboard theme
    4. Sensor installation, cloud connectivity, and customer identifier configuration**

Correct Answer: 4. Sensor installation, cloud connectivity, and customer identifier configuration

Explanation:

A Falcon sensor must be installed correctly, associated with the correct customer environment, and able to communicate with CrowdStrike cloud services. If the host never appears in the console, administrators should verify installation status, customer identifier information, network access, proxy settings, DNS resolution, and firewall connectivity. Dashboard themes or USB policies do not determine whether a sensor registers successfully. Troubleshooting should therefore begin with enrollment and communication fundamentals before investigating unrelated settings or policies.

Question 95.

A company plans to introduce a significantly stricter prevention policy. What is the safest initial rollout strategy?

  1. Apply the policy to a representative pilot group
    2. Deploy it immediately to every endpoint
    3. Disable all sensor updates
    4. Remove existing prevention policies

Correct Answer: 1. Apply the policy to a representative pilot group

Explanation:

A representative pilot group allows administrators to evaluate the effect of stricter prevention settings before the change reaches the entire environment. This makes it possible to identify false positives, application compatibility problems, or unexpected business impact while limiting disruption. Once the policy performs as expected, it can be expanded gradually to additional host groups. Immediate enterprise-wide deployment increases operational risk. A staged rollout is therefore a safer approach for introducing significant prevention changes while maintaining endpoint security and business continuity.

Question 96.

An endpoint is receiving a prevention policy that the administrator did not expect. What should be reviewed first?

  1. Detection comments
    2. Host-group membership, policy assignment, and precedence
    3. Local browser history
    4. Screen resolution

Correct Answer: 2. Host-group membership, policy assignment, and precedence

Explanation:

Unexpected policy application often occurs because an endpoint belongs to multiple host groups or matches a dynamic group rule that was not anticipated. If multiple policies are applicable, policy precedence determines which configuration becomes effective. Reviewing the endpoint’s group memberships, policy targets, and relative priority helps explain why the unexpected policy is being applied. Browser history and display settings have no effect on Falcon policy selection. Understanding host grouping and policy precedence is therefore essential for troubleshooting policy behavior.

Question 97.

A detection shows a workstation actively attempting suspicious outbound connections. What is the most appropriate immediate response action?

  1. Network contain the workstation
    2. Delete the detection
    3. Disable Falcon logging
    4. Uninstall the sensor

Correct Answer: 1. Network contain the workstation

Explanation:

Network containment helps rapidly reduce the risk presented by an endpoint that may be communicating with malicious infrastructure. It restricts most normal network communication while retaining the connectivity needed for Falcon investigation and remediation. This can help interrupt command-and-control traffic, lateral movement, and data exfiltration. Deleting the detection does not stop the endpoint’s behavior, and uninstalling the sensor would remove security visibility. Containment is therefore the appropriate immediate action when a system appears actively compromised and network isolation is required.

Question 98.

A company wants critical servers to stay on a tested Falcon sensor version while user laptops adopt newer versions sooner. What should be configured?

  1. Detection exclusions
    2. Separate sensor update policies
    3. Custom IOAs
    4. Device Control rules

Correct Answer: 2. Separate sensor update policies

Explanation:

Separate sensor update policies allow administrators to manage Falcon sensor versions differently across endpoint populations. Critical servers can remain on a validated version for stability while user laptops receive newer releases sooner. Host groups can be used to assign the correct update policy to each population. This staged approach helps balance operational reliability with timely access to new sensor improvements. Detection exclusions, Custom IOAs, and Device Control do not manage sensor versions. Sensor update policies are therefore the correct mechanism for differentiated rollout strategies.

Question 99.

A newly created Falcon policy is not affecting several intended endpoints. What should the administrator verify first?

  1. Dashboard colors
    2. Local screen resolution
    3. Host-group membership, policy targeting, and precedence
    4. Detection comments

Correct Answer: 3. Host-group membership, policy targeting, and precedence

Explanation:

If a Falcon policy does not affect expected endpoints, the administrator should first confirm that those systems are members of the intended host groups and that the policy is correctly assigned. Dynamic group criteria should also be reviewed if membership is automated. If more than one policy can apply, precedence may cause a different configuration to become effective. Dashboard colors and display settings do not affect policy assignment. Reviewing targeting and precedence is therefore the most direct way to diagnose unexpected policy behavior.

Question 100.

Before deploying major Falcon configuration changes across the enterprise, what should the administrator validate?

  1. Only the policy name
    2. Only the number of managed endpoints
    3. Only dashboard visibility
    4. Targeting, precedence, permissions, endpoint impact, and rollback planning**

Correct Answer: 4. Targeting, precedence, permissions, endpoint impact, and rollback planning

Explanation:

Large-scale Falcon changes should be validated thoroughly before enterprise-wide deployment. Administrators should confirm that the correct host groups are targeted, understand policy precedence, verify administrative permissions, and test the effect on representative endpoints. Application compatibility, performance, and business impact should be considered, and a rollback or recovery plan should be prepared in case unexpected issues occur. A phased deployment further reduces risk. Comprehensive validation helps ensure that security improvements are introduced safely without causing widespread disruption or weakening endpoint protection.