CrowdStrike CCFA Exam
CrowdStrike Certified Falcon Administrator (Page 4 )

Updated On: 30-Jan-2026

Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?

  1. Next-Gen Antivirus (NGAV) protection
  2. Adware and Potentially Unwanted Program detection and prevention
  3. Real-time offline protection
  4. Identification and analysis of unknown executables

Answer(s): D



How can a Falcon Administrator configure a pop-up message to be displayed on a host when the Falcon sensor blocks, kills or quarantines an activity?

  1. By ensuring each user has set the "pop-ups allowed" in their User Profile configuration page
  2. By enabling "Upload quarantined files" in the General Settings configuration page
  3. By turning on the "Notify End Users" setting at the top of the Prevention policy details configuration page
  4. By selecting "Enable pop-up messages" from the User configuration page

Answer(s): C



What is the purpose of precedence with respect to the Sensor Update policy?

  1. Precedence applies to the Prevention policy and not to the Sensor Update policy
  2. Hosts assigned to multiple policies will assume the highest ranked policy in the list (policy with the lowest number)
  3. Hosts assigned to multiple policies will assume the lowest ranked policy in the list (policy with the highest number)
  4. Precedence ensures that conflicting policy settings are not set in the same policy

Answer(s): B



Why is it important to know your company's event data retention limits in the Falcon platform?

  1. This is not necessary; you simply select "All Time" in your query to search all data
  2. You will not be able to search event data into the past beyond your retention period
  3. Data such as process records are kept for a shorter time than event data
  4. Your query will require you to specify the data pool associated with the date you wish to search

Answer(s): B



When would the No Action option be assigned to a hash in IOC Management?

  1. When you want to save the indicator for later action, but do not want to block or allow it at this time
  2. Add the indicator to your allowlist and do not detect it
  3. There is no such option as No Action available in the Falcon console
  4. Add the indicator to your blocklist and show it as a detection

Answer(s): A



Viewing page 4 of 21
Viewing questions 16 - 20 out of 248 questions



Post your Comments and Discuss CrowdStrike CCFA exam prep with other Community members:

Join the CCFA Discussion