CrowdStrike CCFA Exam
CrowdStrike Certified Falcon Administrator (Page 3 )

Updated On: 30-Jan-2026

Which role will allow someone to manage quarantine files?

  1. Falcon Security Lead
  2. Detections Exceptions Manager
  3. Falcon Analyst – Read Only
  4. Endpoint Manager

Answer(s): B



You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?

  1. Go to Host Management in the Host page. Select the host and use the Export Detections button
  2. Utilize the Detection Resolution Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detection Resolution History" section
  3. In the Investigate module, access the Detection Activity page. Use the filters to focus on the appropriate hostname and time, then export the results
  4. Utilize the Detection Activity Dashboard. Use the filters to focus on the appropriate hostname and time, then export the results from the "Detections by Host" section

Answer(s): C



Which of the following is a valid step when troubleshooting sensor installation failure?

  1. Confirm all required services are running on the system
  2. Enable the Windows firewall
  3. Disable SSL and TLS on the host
  4. Delete any available application crash log files

Answer(s): A



What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?

  1. Endpoint ID (EID)
  2. Agent ID (AID)
  3. Security ID (SID)
  4. Computer ID (CID)

Answer(s): B



Where in the Falcon console can information about supported operating system versions be found?

  1. Configuration module
  2. Intelligence module
  3. Support module
  4. Discover module

Answer(s): C



Viewing page 3 of 21
Viewing questions 11 - 15 out of 248 questions



Post your Comments and Discuss CrowdStrike CCFA exam prep with other Community members:

Join the CCFA Discussion