
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 6
4.6 Define Key Data Event Types CCFH Practice Questions (Page 1)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
3concepts
Questions 1–5
- 1
A hunter is investigating a potential data exfiltration incident. The hunter has identified a process that made a large number of outbound connections to a cloud storage service. Which Falcon data event type would provide the most direct evidence of the data being sent?
Select an answer first - 2
In the Falcon platform, what is the primary purpose of file events?
Select an answer first - 3
A Falcon Hunter is reviewing a security alert that indicates a process modified a Windows service configuration. The hunter needs to determine if this change was made by a legitimate administrator or by malware. Which Falcon data event type would provide the most relevant evidence of the modification?
Select an answer first - 4
A Falcon Hunter is analyzing a host that is suspected of running a keylogger. The hunter wants to find evidence of the keylogger writing its output to a file. Which Falcon data event type should the hunter query to detect this behavior?
Select an answer first - 5
A Falcon Hunter is investigating a host that is suspected of downloading a malicious file from a URL. The hunter has identified the file in the download folder but needs to confirm which process initiated the download. Which Falcon data event type would provide the process-level detail needed to trace the download back to its source?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.