Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 4Objective 6

4.6 Define Key Data Event Types CCFH Practice Questions (Page 4)

Part of the Event Search domain, which makes up ~19% of our current practice bank.

18questions here
4free pages
3concepts

Questions 16–18

  1. 16application · medium

    A Falcon Hunter is investigating a suspicious PowerShell process that spawned from a Word document. The hunter needs to determine whether the PowerShell process attempted to modify a Windows registry key to establish persistence. Which Falcon data event type should the hunter query to confirm this behavior?

    Select an answer first
  2. 17foundation · easy

    During a Falcon Event Search, an analyst wants to review the execution of a suspicious binary on an endpoint. Which key data event type would contain the most relevant information for this investigation?

    Select an answer first
  3. 18expert · hard

    A Falcon Hunter is investigating a host that is suspected of running a worm that spreads via network shares. The hunter has identified a process that is making many outbound SMB connections. The hunter needs to determine if the process is also writing files to remote shares. Which combination of Falcon data event types would provide the most complete evidence of this worm behavior?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.