Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 4Objective 4

4.4 Filter Event Data and Analyze Results CCFH Practice Questions (Page 4)

Part of the Event Search domain, which makes up ~19% of our current practice bank.

18questions here
4free pages
2concepts

Questions 16–18

  1. 16expert · medium

    A threat hunter is investigating a series of 'SuspiciousDNSRequest' events. They notice the requests are for a domain that is similar to a legitimate domain but with a typo (e.g., 'gooogle.com'). What is the most likely explanation?

    Select an answer first
  2. 17expert · hard

    A threat hunter is investigating a potential lateral movement. They have identified a series of 'NetworkConnection' events from host A to host B on port 445, followed by 'ProcessRollup2' events on host B. Which filter would best confirm the lateral movement?

    Select an answer first
  3. 18application · medium

    An analyst is looking at 'ProcessRollup2' events and sees a process 'powershell.exe' with a command line that includes 'IEX (New-Object Net.WebClient).DownloadString(...)'. What is the most likely interpretation?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.