Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 3Objective 2

3.2 Differentiate Use of Investigate Module Tools Available in Falcon CCFH Practice Questions (Page 5)

Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.

29questions here
6free pages
9concepts

Questions 21–25

  1. 21application · medium

    An analyst has completed an investigation into a phishing campaign and needs to share the findings with the incident response team. The team wants to see the detection details, the timeline of events, and the related indicators. Which Investigate module feature should the analyst use to share this information?

    Select an answer first
  2. 22application · medium

    An analyst is reviewing a detection that indicates a possible credential theft. The detection details show a series of events, but the analyst needs to understand the full context, including which user was logged in, what processes were running, and any related files. Which Investigate module feature should the analyst use to get this contextual information?

    Select an answer first
  3. 23expert · hard

    An analyst is investigating a detection that shows a series of events, but the timeline appears to have gaps. The analyst suspects that some events were not captured. To understand the full progression, the analyst needs to see all events on the host, including those that may not be directly related to the detection. Which Investigate module feature should the analyst use to get a complete picture?

    Select an answer first
  4. 24foundation · easy

    What is the purpose of a saved search in Falcon Investigate?

    Select an answer first
  5. 25expert · hard

    During an incident investigation, an analyst is examining a detection that shows a series of events: a user opened a malicious attachment, which spawned a process that downloaded a file, and then the file executed. The analyst needs to determine the exact order of these actions and identify any additional processes that ran between them. The analyst also wants to see if any of these processes communicated with external IP addresses. Which combination of Investigate module tools would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.