Skip to content

CCFA Practice Questions

Prepare for CCFA with more than an answer.

222 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$250 USD
Level
Administrator
Valid for
3 years
Domains covered on the exam 8
  1. User Management12.5%
  2. Sensor Deployment12.5%
  3. Host Management and Setup12.5%
  4. Group Creation12.5%
  5. Policy Application12.5%
  6. Rules Configuration12.5%
  7. Dashboards and Reports12.5%
  8. Workflows12.5%
  1. 1

    A security team wants to use the CrowdStrike API to automate the process of downloading sensor installers for different operating systems. Which API service would they need to interact with to accomplish this?

    Show answer details

    Correct answer: C

    The Sensor Download API is specifically designed for this purpose. It allows authorized users to query for available sensor versions for different operating systems and download the installer files programmatically, which is essential for automated deployment workflows in large environments.

  2. 2

    What does it mean if a host is listed on the 'Inactive Sensors' report?

    Show answer details

    Correct answer: B

    A host appears on the 'Inactive Sensors' report when the Falcon sensor installed on it has not checked in with the CrowdStrike cloud for a configurable amount of time (the default is typically 45 days). This could indicate the host was decommissioned, is powered off, or has a persistent network issue.

  3. 3

    An administrator needs to create a custom Indicator of Attack (IOA) rule to detect when any process, except for the legitimate backup tool 'corp_backup.exe', attempts to delete volume shadow copies using vssadmin.exe. Which combination of settings in the IOA rule editor would achieve this?

    Show answer details

    Correct answer: D

    The IOA rule editor allows for both detection criteria and exclusion criteria within the same rule. The correct approach is to define the malicious behavior (vssadmin deleting shadows) in the main rule logic and then add an exclusion specifically for the parent/source process that is allowed to perform this action ('corp_backup.exe'). This creates a single, precise rule.

  4. 4

    A hospital's IT department is preparing to deploy the Falcon sensor to critical medical imaging workstations. These workstations use a proprietary, resource-intensive application that is known to conflict with some security software. To minimize patient care disruption, the administrator wants to initially deploy the sensor in a non-intrusive mode. Which prevention policy setting is most appropriate for this initial deployment phase?

    Show answer details

    Correct answer: B

    Setting the prevention policy sliders to 'Detect Only' mode allows the Falcon sensor to be fully operational in terms of monitoring and logging all suspicious activities without actively blocking or killing any processes. This is the ideal mode for an initial 'burn-in' period on sensitive systems, as it allows administrators to observe potential conflicts and false positives before enabling active prevention.

  5. 5

    A large e-commerce company is deploying Falcon sensors to its fleet of virtual servers that handle customer transactions. These servers are part of a non-persistent VDI pool, where instances are created and destroyed based on demand. After deploying the sensor to the golden image, the security team observes that newly spawned VDI instances are experiencing significant CPU and I/O overhead during their initial startup, impacting application performance.

    The VDI architecture involves a management server that provisions new instances from a master golden image stored on a SAN. The team needs a strategy to minimize the sensor's performance impact during the VDI boot and provisioning process while ensuring each new instance is fully protected as quickly as possible.

    Which strategy should the administrator implement to resolve the performance issues?

    graph TD subgraph VDI Infrastructure VDI_MGR[VDI Management Server] -->|Provisions| POOL[VDI Pool] SAN[(Golden Image on SAN)] --> VDI_MGR POOL -- contains --> VDI1(VDI Instance 1) POOL -- contains --> VDI2(VDI Instance 2) POOL -- contains --> VDI_N(VDI Instance N) end subgraph User Access USER[End User] --> LB[Load Balancer] LB --> POOL end
    Show answer details

    Correct answer: D

    The 'Sensor-based Machine Learning for VDI' setting is specifically designed to optimize sensor performance in non-persistent VDI environments. It reduces the initial resource overhead on newly created instances by streamlining the ML model loading and initialization processes. Installing the sensor on the golden image is correct, and applying this specialized policy addresses the performance problem directly without compromising security or requiring complex scripting.

  6. 6

    A financial institution is deploying the Falcon sensor to a fleet of Linux servers running a mix of CentOS 7 and Rocky Linux 9. The deployment script fails on the Rocky Linux 9 servers with an error indicating an unsupported kernel. The CentOS 7 servers install successfully. What is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    CrowdStrike regularly updates the Falcon sensor to support new operating system versions and kernels. A common cause for installation failure on a newer OS version, when it succeeds on an older one, is that the installer package being used does not yet support the newer kernel. The administrator should download the latest sensor version from the Falcon UI and use it for the Rocky Linux 9 deployment.

  7. 7

    An administrator is designing a host group structure for a large enterprise with distinct business units (e.g., Finance, Engineering, Marketing) and environments (e.g., Production, Staging, Development). The goal is to apply tailored prevention policies based on both business unit and environment. Which host grouping strategy is most effective and scalable?

    Show answer details

    Correct answer: C

    Dynamic host groups are the most scalable and manageable solution. By leveraging criteria like Active Directory Organizational Units (OUs), hostname prefixes/suffixes, or sensor tags, hosts can be automatically placed into the correct group upon installation. This ensures the correct policies are applied immediately without manual intervention, reducing administrative overhead and the risk of misconfiguration.

  8. 8

    A security analyst needs to create a custom IOA rule to detect a specific LOLBAS (Living Off the Land Binary and Script) technique where PowerShell is used to download a file from a remote server and then execute it. The rule should only trigger if the command line contains both 'DownloadString' and 'IEX' (Invoke-Expression). Which TWO of the following regular expressions would be most effective when used in the Command Line field of the custom IOA rule? (Select TWO)

    Show answer details

    Correct answer: A, B

    To ensure the rule triggers regardless of the order in which 'DownloadString' and 'IEX' appear in the command line, two separate regex patterns are needed. '.*DownloadString.IEX.' matches cases where 'DownloadString' appears first, and '.*IEX.DownloadString.' matches cases where 'IEX' appears first. Using both covers the necessary permutations for this detection logic.

  9. 9

    A global retail company wants to automate its initial response to high-severity ransomware detections. The Security Operations Center (SOC) team has defined a specific workflow they want to implement using Falcon Fusion.

    The desired workflow is as follows: When a high-severity detection with a tactic of 'Ransomware' occurs, the system should immediately contain the affected host to prevent lateral movement. Simultaneously, a high-priority ticket should be created in their Jira instance with details of the detection, and a notification should be sent to the #soc-alerts Slack channel. The workflow should only apply to hosts in the 'Production Servers' group.

    Which sequence of components in a Falcon Fusion workflow would correctly implement this requirement?

    Show answer details

    Correct answer: A

    This option correctly defines the workflow. The trigger is a new detection. The condition correctly filters for only the specified detections (High severity, Ransomware tactic, in the 'Production Servers' group). The actions (Contain, Jira, Slack) are the required response steps. This structure ensures the automation is precise and executes all required steps.

  10. 10

    True or False: To uninstall the Falcon sensor from a Windows host via the command line when uninstall protection is enabled, an administrator must first retrieve a unique, time-sensitive maintenance token from the Falcon UI and use it as a parameter in the uninstall command.

    Show answer details

    Correct answer: A

    This statement is true. When uninstall protection is enabled in the Sensor Update Policy, a maintenance token is required to perform administrative actions like uninstalling or manually upgrading the sensor. This token must be generated from the Host Management page for the specific host and is required to prevent unauthorized removal of the sensor.

Create an account to continue.