
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 4Objective 4
4.4 Filter Event Data and Analyze Results CCFH Practice Questions (Page 4)
Part of the Event Search domain, which makes up ~19% of our current practice bank.
18questions here
4free pages
2concepts
Questions 16–18
- 16
A threat hunter is investigating a series of 'SuspiciousDNSRequest' events. They notice the requests are for a domain that is similar to a legitimate domain but with a typo (e.g., 'gooogle.com'). What is the most likely explanation?
Select an answer first - 17
A threat hunter is investigating a potential lateral movement. They have identified a series of 'NetworkConnection' events from host A to host B on port 445, followed by 'ProcessRollup2' events on host B. Which filter would best confirm the lateral movement?
Select an answer first - 18
An analyst is looking at 'ProcessRollup2' events and sees a process 'powershell.exe' with a command line that includes 'IEX (New-Object Net.WebClient).DownloadString(...)'. What is the most likely interpretation?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.