
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 1
6.1 Analyze and Recognize Suspicious Overt Malicious Behaviors CCFH Practice Questions (Page 1)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
15questions here
3free pages
4concepts
Questions 1–5
- 1
A Falcon Hunter is investigating a series of events on a network. The events show that a user's machine made a connection to a malicious domain, then downloaded a file, and then the file was executed. The file then made a connection to a different IP address. Which attack pattern does this sequence most closely align with?
Select an answer first - 2
A Falcon Hunter observes a series of events on a server: a PowerShell script downloads an executable, the executable runs with a command line that includes ' -enc ' followed by a long base64 string, and then the process spawns a child process that makes a network connection to an IP address in a foreign country. Which attack pattern does this sequence most closely align with?
Select an answer first - 3
A user runs a script that modifies several registry keys and creates a new scheduled task. The script is not signed and has never been seen before. Which analytical approach best distinguishes a benign anomaly from a potential threat?
Select an answer first - 4
An analyst has two alerts: Alert A shows a single failed login attempt on a user account, and Alert B shows a process creating a scheduled task and connecting to a known malicious IP address. Which alert should be prioritized for investigation?
Select an answer first - 5
Which factor is most important when determining the severity of an alert for prioritization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.