
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 6
6.6 Recognize Patterns Such as an Enterprise-Wide File Infection Process to Determine the Root Cause or Source of the Infection CCFH Practice Questions (Page 2)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
19questions here
4free pages
3concepts
Questions 6–10
- 6
In a file-encrypting malware investigation, you find that the first encrypted file on each host was created by a process that had a parent process of 'powershell.exe'. On the earliest host, the PowerShell process was started by a user who had just opened an email attachment. What is the most likely root cause?
Select an answer first - 7
You are hunting for the source of a file-encrypting malware. You have identified that the malware process on each host creates a unique mutex. You also notice that the mutex name is the same on all hosts. What does this indicate?
Select an answer first - 8
A file-encrypting malware has affected hosts in two different office locations. In location A, the first infected host received a phishing email. In location B, the first infected host was a server that had a vulnerable internet-facing service. What is the most likely root cause?
Select an answer first - 9
You are hunting for the source of a file-encrypting malware that has affected 50 hosts. Telemetry shows that the first encrypted file on each host was created by a process that ran under the same user account. Which query would best help you identify the initial execution time and source host?
Select an answer first - 10
Which of the following telemetry data is most useful for identifying the source of an infection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.