
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 3Objective 1
3.1 Analyze and Interpret Metadata Around Files and Processes Recorded by Falcon CCFH Practice Questions (Page 4)
Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.
19questions here
4free pages
4concepts
Questions 16–19
- 16
In a threat-hunting search, you want to find processes that were launched from a temporary directory, which is a common sign of malware. Which metadata field should you filter on?
Select an answer first - 17
An analyst is investigating a file that was executed on a host. The file's metadata shows a creation timestamp of 2023-05-10 14:32:00 UTC and a last-write timestamp of 2023-05-10 14:32:05 UTC. The file is named 'update_installer.exe' and is located in C:\Users\Public\Downloads. The analyst also sees a process event for the same file with a start timestamp of 2023-05-10 14:32:10 UTC. What does the 5-second gap between the last-write and process start suggest?
Select an answer first - 18
A Falcon event shows a file with a SHA256 hash. What does this metadata field uniquely identify?
Select an answer first - 19
An analyst is reviewing a file alert for 'C:\Windows\Temp\tmp1234.tmp'. The file's size is 0 bytes, and its creation timestamp is 30 seconds before a known malicious process started. Which interpretation of the file metadata is MOST accurate?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.