
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 4
4.4 Filter Event Data and Analyze Results CCFH Practice Questions (Page 3)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
2concepts
Questions 11–15
- 11
After filtering Event Search results for a specific process name, a hunter notices a large number of events from a single, rarely-used admin account. What is the most important initial conclusion to draw from this pattern?
Select an answer first - 12
An analyst is looking at 'UserAccount' events and sees a user 'svc_backup' logging in from a new IP address at 3:00 AM. The user account is a service account. What is the most likely explanation?
Select an answer first - 13
After filtering for all process creation events (event_simpleName=ProcessRollup2) in the last 24 hours, an analyst notices a high volume of 'cmd.exe' executions from a single host. What is the most appropriate next step to determine if this is malicious?
Select an answer first - 14
A threat hunter is investigating a potential privilege escalation. They have identified a 'ProcessRollup2' event where a process 'cmd.exe' was started by a process 'winlogon.exe'. What is the most likely interpretation?
Select an answer first - 15
A security team is investigating a potential data breach. They have identified a large number of 'FileRead' events from a sensitive folder on a server. The events are coming from a single user account. What is the most important next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.