
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 6
4.6 Define Key Data Event Types CCFH Practice Questions (Page 2)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
3concepts
Questions 6–10
- 6
A Falcon Hunter is investigating a host that is suspected of running a malware that uses a reflective DLL injection technique. The hunter has identified a process that is loading a DLL from memory without writing it to disk. Which Falcon data event type would provide the most relevant evidence of this behavior?
Select an answer first - 7
A Falcon Hunter is investigating a host that is suspected of being used as a proxy to relay malicious traffic. The hunter has identified a process that is making many inbound and outbound connections. Which Falcon data event type would provide the most relevant evidence of this relay activity?
Select an answer first - 8
When investigating a potential malware infection, an analyst sees a file event showing a new executable created in a user's temp folder. Which additional event type would be most useful to confirm whether the executable was actually run?
Select an answer first - 9
A Falcon Hunter is investigating a host that is suspected of running a credential dumping tool. The hunter has identified a process that is accessing the LSASS process memory. Which Falcon data event type would provide the most relevant evidence of this behavior?
Select an answer first - 10
An analyst is comparing process events and network events to understand an attacker's actions. Which attribute is unique to network events and not typically found in process events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.