
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 2Objective 2
2.2 Analyze the Information Displayed in the Process Timeline to Understand the Flow of Events and Detections CCFH Practice Questions (Page 5)
Part of the Detection Analysis domain, which makes up ~10% of our current practice bank.
28questions here
6free pages
6concepts
Questions 21–25
- 21
You are analyzing a Process Timeline and notice a pattern: a legitimate application (e.g., a document editor) spawns a child process that is not typical for that application. The child process then attempts to access the network. What does this pattern suggest?
Select an answer first - 22
You are analyzing a Process Timeline and see a process (e.g., svchost.exe) that has spawned multiple child processes. One of the children is a known malicious process, but the others appear benign. What should you do?
Select an answer first - 23
You are investigating a detection that occurred at 10:00 AM. The Process Timeline shows events from 9:00 AM to 11:00 AM. You need to determine if there were any precursor events before the detection. What is the most effective way to do this?
Select an answer first - 24
When interpreting the chronological sequence of events in the Process Timeline, what does the left-to-right ordering of events on the timeline bar represent?
Select an answer first - 25
What is the primary purpose of analyzing the flow of events in the Process Timeline during a detection investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.