Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 3Objective 4

3.4 Interpret Search Result Information Displayed in Dashboards to Determine Additional Investigation or Action CCFH Practice Questions (Page 2)

Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.

10questions here
2free pages
1concept

Questions 6–10

  1. 6application · medium

    A security analyst is reviewing the 'Detections Summary' dashboard and sees a detection with a 'Critical' severity and a 'High' confidence score. The detection is for 'Ransomware' on a single endpoint. The 'Prevention' policy for that endpoint shows the action was 'Blocked'. The endpoint's last seen time in the dashboard is 2 minutes ago. What should the analyst do NEXT based on this dashboard information?

    Select an answer first
  2. 7application · medium

    A Falcon admin is reviewing the 'Vulnerability Management' dashboard and sees a widget showing 'Top Exploited CVEs'. The top CVE is 'CVE-2024-5678' with a 'Critical' severity and a 'Known Exploited' tag. The admin clicks on the CVE and sees that it affects 20 endpoints, all in the 'DMZ' group. The 'Patch' status shows 'Not Patched' for all 20. What is the MOST appropriate action based on this dashboard data?

    Select an answer first
  3. 8application · medium

    An analyst is reviewing the 'Falcon X' dashboard and sees a widget showing 'Top Users with Detections'. The top user is 'jsmith' with 10 detections. The analyst clicks on 'jsmith' and sees that all 10 detections are for 'PUA.Win.Tool.Mikatz' (a known credential-dumping tool). The 'Last Seen' for the endpoint is 5 minutes ago. What is the MOST appropriate action based on this dashboard data?

    Select an answer first
  4. 9application · medium

    A Falcon admin is reviewing the 'IOA (Indicators of Attack)' dashboard and sees a detection for 'Credential Dumping' on a domain controller. The detection has a 'Medium' severity and a 'Low' confidence score. The 'Prevention' action shows 'Blocked'. The admin also sees a related 'Detection' for 'Mimikatz' on the same endpoint with 'High' severity and 'High' confidence. What is the MOST appropriate interpretation of this dashboard data?

    Select an answer first
  5. 10application · medium

    An analyst is reviewing the 'Event Dashboard' and sees a spike in 'Process Creation' events from a specific endpoint over the last 15 minutes. The events show a pattern of 'powershell.exe' spawning 'cmd.exe' repeatedly. The endpoint is a standard user workstation. What is the MOST appropriate next step based on this dashboard pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.