
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 3Objective 2
3.2 Differentiate Use of Investigate Module Tools Available in Falcon CCFH Practice Questions (Page 4)
Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.
29questions here
6free pages
9concepts
Questions 16–20
- 16
During an investigation, an analyst is looking at a detection that involves multiple hosts and a shared file. The analyst wants to see how the file was propagated across the hosts and identify any other entities that interacted with the file. The analyst also needs to determine if there is a common source for the file. Which Investigate module tool would be most effective for this analysis?
Select an answer first - 17
Which of the following data types can be queried using the Falcon Investigate search bar?
Select an answer first - 18
An analyst is investigating a user who has been flagged for unusual activity. The analyst wants to see all hosts the user has logged into, the files they have accessed, and any detections associated with the user. The analyst also wants to see if any of these hosts have communicated with known malicious IPs. Which Investigate module feature should the analyst use to get a comprehensive view?
Select an answer first - 19
In Falcon Investigate, what is the purpose of applying a filter to a search?
Select an answer first - 20
How can a Falcon analyst share a saved search with other team members?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.