
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 4
4.4 Filter Event Data and Analyze Results CCFH Practice Questions (Page 2)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
2concepts
Questions 6–10
- 6
A security analyst is investigating a potential malware infection. They have identified a 'FileWrite' event to a suspicious path, but the file is not in the 'KnownMalware' list. What is the most appropriate next step?
Select an answer first - 7
An analyst is reviewing 'ProcessRollup2' events and sees a process 'rundll32.exe' with a command line that includes a path to a file in the 'AppData' folder. What is the most likely interpretation?
Select an answer first - 8
An analyst is reviewing 'NetworkConnection' events and sees a host making connections to a known malicious IP on a non-standard port. The connections are encrypted. What is the most likely explanation?
Select an answer first - 9
An analyst is reviewing a series of 'UserAccount' events and notices a user account was created and then immediately added to the 'Domain Admins' group. What is the most likely conclusion from this pattern?
Select an answer first - 10
An analyst is investigating a series of 'SuspiciousDNSRequest' events. They notice the requests are occurring at regular 5-minute intervals. What does this pattern suggest?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.