Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 3Objective 2

3.2 Differentiate Use of Investigate Module Tools Available in Falcon CCFH Practice Questions (Page 3)

Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.

29questions here
6free pages
9concepts

Questions 11–15

  1. 11application · medium

    An analyst is investigating a suspicious file that was detected on multiple hosts. The analyst wants to find all hosts that have this file and see if any other files with similar names exist on those hosts. Which Investigate module feature should the analyst use to explore the file entity?

    Select an answer first
  2. 12foundation · easy

    In Falcon Investigate, what does entity exploration allow an analyst to do?

    Select an answer first
  3. 13application · medium

    An analyst has identified a new indicator of compromise (IOC) and wants to share it with the threat intelligence team. The analyst also wants to create a query that can be used to search for this IOC across all hosts. Which Investigate module feature should the analyst use?

    Select an answer first
  4. 14foundation · easy

    What is a facet in the context of Falcon Investigate search results?

    Select an answer first
  5. 15foundation · easy

    When analyzing an event timeline in Falcon, what should an analyst look for to understand the progression of an incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.