CCFA Sample Questions & Answers
Eight equally weighted areas run through managing user roles and API keys, Falcon sensor prerequisites and default policies, filtering and grouping hosts, prevention-policy settings, custom IOA rules, sensor reports, and workflow configuration.
Launch the full CCFA simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Rules Configuration · Assess IOC settings required for customized security posturing and to manage false positives
An administrator is managing a large number of custom IOCs. To improve performance and reduce clutter, they decide to set an expiration date for IOCs related to a specific, now-remediated campaign. What happens when a custom IOC reaches its expiration date?
Show answer & explanation
Correct answer: A
When an IOC's expiration date is reached, it is automatically disabled, meaning it will no longer generate detections on endpoints. However, it is not immediately deleted. The IOC remains in the system in a disabled state for a retention period (typically 90 days), after which it is permanently removed. This allows for auditing and potential re-activation if needed.
- Question 2Intermediate
Dashboards and Reports · Understand the different audit logs and their use cases
A new Falcon administrator is reviewing the available audit logs to understand user activity within the console. Which audit log should they consult to find a record of users who have used Real-Time Response (RTR) to connect to a host and the specific commands they executed during their session?
Show answer & explanation
Correct answer: C
The Real-Time Response Audit Log is specifically designed to capture all RTR activity. It provides a detailed record of which user initiated a session on which host, the start and end times of the session, and a full list of all commands that were executed, including both the input commands and their output.
- Question 3Advanced
Policy Application · Determine the appropriate sensor update policy settings in order to control the update process
A company's policy requires that all Falcon sensor updates are first tested on a pilot group of non-critical systems for one week before being promoted to production. The production systems should remain on the currently approved version during this testing period. How can an administrator configure Sensor Update Policies to enforce this?
Show answer & explanation
Correct answer: B
This approach provides the most control and meets the requirements. The pilot group policy set to 'Latest Version' or 'N-1' will automatically receive new updates for testing. The production group policy is locked to a specific, validated version, preventing unintended updates. After the one-week test, the administrator can update the production policy to the new version, ensuring a controlled, staged rollout.
- Question 4Intermediate
Rules Configuration · Interpret business requirements in order to allow trusted activity, resolve false positives and fix performance issues
A developer at a software company frequently compiles a custom, in-house application named 'DataCruncher.exe'. Each compilation results in a new file hash, causing repeated Machine Learning (ML) detections and quarantines, which disrupts their workflow. The application is always located in 'D:\dev_builds'. What is the most precise and secure method to create an ML exclusion for this scenario?
Show answer & explanation
Correct answer: B
Excluding the specific file path is the most precise method. It allows only 'DataCruncher.exe' within that directory to be excluded, while any other potentially malicious file dropped into 'D:\dev_builds' would still be inspected by Falcon. Excluding the entire directory ('D:\dev_builds*') would create a security blind spot. Using a hash is not viable as it changes with each compilation.
- Question 5Beginner
Sensor Deployment · Determine prerequisites to successfully install a Falcon sensor on supported operating systems
What is the primary purpose of assigning a Customer ID (CID) during the Falcon sensor installation?
Show answer & explanation
Correct answer: B
The Customer ID (CID) is a unique identifier that associates the installed sensor with a specific customer's environment (tenant) in the CrowdStrike cloud. This ensures that the host checks in correctly, sends its data to the right location, and receives the appropriate policies and configurations from the correct Falcon console.
- Question 6IntermediateSelect 2
Host Management and Setup · Explain the impact of Reduced Functionality Mode (RFM) and why it might be caused
A host has been placed into Reduced Functionality Mode (RFM). Which of the following statements accurately describes the host's protection status? (Select TWO)
Show answer & explanation
Correct answers: B, D
RFM is typically caused by a kernel incompatibility. This results in the sensor disabling its kernel-level drivers, which are responsible for real-time process monitoring and prevention. However, the sensor is not completely offline. User-mode components, such as scanning files on disk with Machine Learning, can remain operational, providing a limited layer of protection.
- Question 7Intermediate
User Management · Create roles and assign users to roles based on desired permissions
An administrator needs to create a new user role for a junior SOC analyst team. This role should allow analysts to view detections and process trees, acknowledge detections, and run basic informational commands in Real-Time Response (like 'ls' or 'ps'). However, they should NOT be able to contain hosts, delete files, or run commands that modify the system state. Which pre-defined role is the best foundation to clone and modify for this purpose?
Show answer & explanation
Correct answer: B
The 'Real Time Responder - Read Only Analyst' role is the most appropriate starting point. It provides the necessary read-only access to detections and RTR sessions, allowing for investigation without granting powerful, system-modifying capabilities. The administrator can then add permissions like 'Acknowledge Detections' to this cloned role to meet the full set of requirements.
- Question 8Beginner
Group Creation · Determine the appropriate group assignment for endpoints and understand how this impacts the application of policies
When creating a dynamic host group, which of the following is NOT a valid criterion that can be used in the assignment rule?
Show answer & explanation
Correct answer: C
Dynamic host group assignment is based on relatively static host attributes reported by the sensor, such as hostname, OS version, OU, site name, sensor version, or tags. It does not use real-time performance metrics like CPU utilization, memory usage, or network bandwidth as criteria for group assignment.
- Question 9Advanced
Policy Application · Configure a containment policy for IP address or subnet exclusions that will apply to network contained hosts
A Falcon administrator has configured a containment policy to allow specific IP addresses for remote management tools. During an incident, a host is network contained. An analyst finds they are unable to connect to the contained host from their management workstation, even though its IP was added to the containment policy's allowlist. The analyst confirms there are no network firewalls blocking the connection. What is a common reason for this failure?
Show answer & explanation
Correct answer: A
Containment policies, like other policies, must be explicitly assigned to host groups to be effective. If the host is in a group that does not have the updated containment policy assigned to it, it will use the default or another assigned policy, which may not have the analyst's IP address on the allowlist. This is a common oversight when managing multiple policies and groups.
- Question 10Intermediate
Workflows · Configure workflows to respond to defined triggers
A Falcon Fusion workflow can be configured to automatically enrich detection data by querying an external threat intelligence platform via its API.
Show answer & explanation
Correct answer: A
True. Falcon Fusion workflows include actions to make custom API calls ('HTTP Request'). This allows administrators to build automation that takes an indicator from a detection (like a domain, IP, or hash), queries an external service, and can then use the response to update the detection, create a ticket, or trigger further actions.
Ready for the real thing?
The full CCFA simulator has every exam-style question, timed mode, and instant scoring.