Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 3Objective 1

3.1 Analyze and Interpret Metadata Around Files and Processes Recorded by Falcon CCFH Practice Questions (Page 4)

Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.

19questions here
4free pages
4concepts

Questions 16–19

  1. 16foundation · easy

    In a threat-hunting search, you want to find processes that were launched from a temporary directory, which is a common sign of malware. Which metadata field should you filter on?

    Select an answer first
  2. 17application · medium

    An analyst is investigating a file that was executed on a host. The file's metadata shows a creation timestamp of 2023-05-10 14:32:00 UTC and a last-write timestamp of 2023-05-10 14:32:05 UTC. The file is named 'update_installer.exe' and is located in C:\Users\Public\Downloads. The analyst also sees a process event for the same file with a start timestamp of 2023-05-10 14:32:10 UTC. What does the 5-second gap between the last-write and process start suggest?

    Select an answer first
  3. 18foundation · easy

    A Falcon event shows a file with a SHA256 hash. What does this metadata field uniquely identify?

    Select an answer first
  4. 19application · medium

    An analyst is reviewing a file alert for 'C:\Windows\Temp\tmp1234.tmp'. The file's size is 0 bytes, and its creation timestamp is 30 seconds before a known malicious process started. Which interpretation of the file metadata is MOST accurate?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.