
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 1
6.1 Analyze and Recognize Suspicious Overt Malicious Behaviors CCFH Practice Questions (Page 2)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
15questions here
3free pages
4concepts
Questions 6–10
- 6
A Falcon Hunter is reviewing telemetry for a workstation. The telemetry shows that a process named 'rundll32.exe' executed a DLL file from the user's Temp folder, and then the process made a network connection to a domain that was recently registered. Which behavior is the most overt sign of malicious activity?
Select an answer first - 7
Which telemetry event is most clearly an overt malicious behavior?
Select an answer first - 8
An analyst observes a sequence of events: an email attachment is opened, a macro runs, a PowerShell command downloads a payload, and the payload establishes a connection to an external IP. Which attack pattern does this sequence most closely align with?
Select an answer first - 9
Which of the following behaviors, when observed together, most strongly correlates with the tactic of credential access?
Select an answer first - 10
Which of the following is an example of an overt malicious behavior that would be clearly visible in endpoint telemetry?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.