
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 6
4.6 Define Key Data Event Types CCFH Practice Questions (Page 3)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
3concepts
Questions 11–15
- 11
An organization suspects a malware infection that downloads a payload from a remote server and then writes a malicious executable to disk. The hunter wants to trace the full sequence of events. Which combination of Falcon data event types would provide the most complete picture of this activity?
Select an answer first - 12
A Falcon hunter is investigating a potential data exfiltration attempt. Which key data event type would be most useful to examine for evidence of outbound communication?
Select an answer first - 13
A Falcon Hunter is investigating a host that is suspected of running a malware that uses a fileless technique to execute code from the registry. The hunter has identified a process that is reading a registry key that contains encoded data. Which Falcon data event type would provide the most relevant evidence of this behavior?
Select an answer first - 14
A Falcon analyst is investigating a suspicious registry modification that may indicate persistence. Which data event type is the source of this information?
Select an answer first - 15
A Falcon Hunter is analyzing a host that is suspected of running a ransomware strain. The hunter wants to identify the files that were encrypted by the malware. Which Falcon data event type would provide the most direct evidence of the file encryption activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.