
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 3
6.3 Evaluate Information for Reliability, Validity and Relevance for Use in the Process of Elimination CCFH Practice Questions (Page 2)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
16questions here
4free pages
4concepts
Questions 6–10
- 6
During a hunt for a specific malware family, an analyst encounters a log entry showing a benign software update. How should this information be classified in terms of relevance?
Select an answer first - 7
A Falcon Hunter is investigating a potential credential-theft campaign. A junior analyst provides a Falcon Intelligence Premium report from a third-party researcher claiming that a specific malware family is the primary tool used in the campaign. The hunter notices the report cites only one source—a single blog post—and the indicators listed do not match any telemetry in the environment. According to the process of elimination, what should the hunter do with this report?
Select an answer first - 8
A Falcon Hunter is investigating a potential supply-chain attack. The hunter has four pieces of information: (1) a Falcon event showing a signed binary from a trusted vendor executing on a server, (2) a public CVE advisory for that vendor's product, (3) a blog post from an unknown researcher claiming the vendor is compromised, and (4) a Falcon event showing the same binary communicating with an external IP not in the vendor's known infrastructure. The hunter must decide which information to use for further hunting. Which piece of information should the hunter prioritize?
Select an answer first - 9
A Falcon Hunter is triaging a large set of alerts from a single host. The host is a domain controller with a known, approved administrative script that runs daily. The alerts include: (1) a script execution matching the approved script's hash, (2) a PowerShell command invoking a network share, and (3) a scheduled task creation. The hunter has limited time and must decide which alerts to investigate first. The approved script is documented in the change management system, and the network share is a known admin share. The scheduled task creation is not documented. Which alert should the hunter prioritize for investigation?
Select an answer first - 10
A Falcon Hunter is triaging a set of alerts from a compromised host. The alerts include: (1) a PowerShell script downloading a file from a known malicious domain, (2) a scheduled task creation, and (3) a legitimate software update. The hunter has limited time and must decide which alerts to investigate first. The PowerShell script is documented in a threat intel report, the scheduled task is not documented, and the software update is from a trusted vendor. Which alert should the hunter deprioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.