
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 5Objective 3
5.3 Leverage the Events Reference (Events Data Dictionary) Documentation to Learn Information About Specific Events CCFH Practice Questions (Page 4)
Part of the Reports and References domain, which makes up ~8% of our current practice bank.
22questions here
5free pages
5concepts
Questions 16–20
- 16
When reviewing the Events Reference for a network event, an analyst sees the field 'LocalPort' listed. What data type and meaning would the analyst expect for this field?
Select an answer first - 17
A Falcon Hunter is investigating a suspicious PowerShell command and sees an event named 'ProcessRollup2' in the Event Search. They want to read the official documentation for this event. What is the most efficient way to find it in the Events Reference?
Select an answer first - 18
While hunting, an analyst sees an event type 'SuspiciousDNSRequest' in the Event Viewer. The analyst is unfamiliar with this event. What is the first step the analyst should take to understand and respond to this event?
Select an answer first - 19
A Falcon Hunter is writing a custom detection rule and needs to filter on a field that indicates the parent process ID. They are unsure of the exact field name. They have access to the Events Reference. What is the best way to find the correct field name?
Select an answer first - 20
A Falcon Hunter is investigating an incident and needs to understand a specific event that is not well-known. They have access to the Falcon console but are not sure if the Events Reference is available to them. What is the best way to determine if they can access it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.