CrowdStrike CCFA Exam
CrowdStrike Certified Falcon Administrator (Page 2 )

Updated On: 30-Jan-2026

What is the function of a single asterisk (*) in an ML exclusion pattern?

  1. The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path
  2. The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path
  3. The single asterisk is the insertion point for the variable list that follows the path
  4. The single asterisk is only used to start an expression, and it represents the drive letter

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/machine-learning



Once an exclusion is saved, what can be edited in the future?

  1. All parts of the exclusion can be changed
  2. Only the selected groups and hosts to which the exclusion is applied can be changed
  3. Only the options to "Detect/Block" and/or "File Extraction" can be changed
  4. The exclusion pattern cannot be changed

Answer(s): B



In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor Update Policy would meet this criteria?

  1. Sensor version set to N-1 and Bulk maintenance mode is turned on
  2. Sensor version fixed and Uninstall and maintenance protection turned on
  3. Sensor version updates off and Uninstall and maintenance protection turned off
  4. Sensor version set to N-2 and Bulk maintenance mode is turned on

Answer(s): B



You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?

  1. Prevention Policy Audit Trail
  2. Prevention Policy Debug
  3. Prevention Hashes Ignored
  4. Machine-Learning Prevention Monitoring

Answer(s): A



What is the maximum number of patterns that can be added when creating a new exclusion?

  1. 10
  2. 0
  3. 1
  4. 5

Answer(s): D



Viewing page 2 of 21
Viewing questions 6 - 10 out of 248 questions



Post your Comments and Discuss CrowdStrike CCFA exam prep with other Community members:

Join the CCFA Discussion