CCFA Exam QuestionsBrowse all questions from this exam

CCFA Exam - Question 20


How long are detection events kept in Falcon?

Show Answer
Correct Answer: B

Detection events in Falcon are kept for the duration of your subscribed data retention period. This means the retention period can vary depending on the specific terms of the subscription agreement with Falcon. Different customers could have different data retention periods, tailored to their needs and the service level they have subscribed to.

Discussion

10 comments
Sign in to comment
plantvastOption: B
Jan 20, 2023

The wording of the question makes this confusing. Detections themselves are kept for 90 days but event data is only kept for the event retention set.

options862Option: A
Apr 9, 2023

Option - A Note: CrowdStrike keeps detection data in the cloud for 90 days, after which some of the data gets purged from the database. Null icons indicate that some of the data for a process has started to be nullified. It could be a missing tactic, label, metadata or any part of the information pertaining to that process.

FerbOPOption: A
Apr 25, 2023

A is correct

SoFi443Option: B
May 28, 2023

I think the right answer should be B

sbag0024Option: A
Jun 14, 2023

Shoot it Could be A.Per the CCFA Checklist Notes " Data is only available in the Falcon UI for investigations, etc. through the company’s data retention time frame; detection information is kept for 90 days regardless; UI audits are available for 1 year

ManuneethiOption: A
Jul 16, 2023

90 days only

Synecdoque19Option: B
May 30, 2023

Activity feed (alerts) are kept 90 days. Events (EAM Data) depends on your contract

sbag0024Option: C
Jun 9, 2023

I Think this is C, It says Detection Events. Events are stored for 7 Days

sbag0024Option: B
Jun 14, 2023

Going to go with B, its either B or C . Bad question really.

silva222222Option: A
May 22, 2024

https://www.crowdstrike.com/products/endpoint-security/falcon-insight-edr/faq/