nerdexam
CrowdStrike

CCFA-200B · Question #164

How do user permissions function in Falcon?

The correct answer is D. User permissions are cumulative, the more roles assigned to a user the more capabilities they. In Falcon, user permissions work on a cumulative (additive) model - each role assigned to a user adds capabilities on top of existing ones, so assigning more roles expands what a user can do, never restricts it. This makes D correct. Why the distractors are wrong: A is false…

Platform Administration

Question

How do user permissions function in Falcon?

Options

  • ACustom user role permission sets are shared with all CrowdStrike customers globally
  • BEach Falcon permission needs to be selected when the user account is created
  • CUser permissions grow more restrictive, the more roles assigned to a user the less capabilities
  • DUser permissions are cumulative, the more roles assigned to a user the more capabilities they

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    2% (1)
  • D
    90% (56)

Explanation

In Falcon, user permissions work on a cumulative (additive) model - each role assigned to a user adds capabilities on top of existing ones, so assigning more roles expands what a user can do, never restricts it. This makes D correct.

Why the distractors are wrong:

  • A is false because custom role permission sets are tenant-specific; they are not shared across CrowdStrike customers - each organization manages its own roles in isolation.
  • B is false because Falcon uses a role-based access control (RBAC) model, not a permission-by-permission selection at account creation; you assign predefined roles, not individual permissions.
  • C describes the opposite of how Falcon works - permissions are never subtracted by adding roles; the system is purely additive.

Memory tip: Think of Falcon roles like stack of coupons - each one you add gives you more discounts, never takes any away. More roles = more access, always.

Topics

#user permissions#RBAC#cumulative roles#Falcon user management

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice