
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 3Objective 3
3.3 Understand Use Cases for Various Search Options (e.g., Users, Hosts, Hash Search, IP Addresses, and Bulk Domains) CCFH Practice Questions (Page 1)
Part of the Search and Investigation Tools domain, which makes up ~12% of our current practice bank.
15questions here
3free pages
6concepts
Questions 1–5
- 1
An organization has identified a malicious domain that is being used for data exfiltration. The security team wants to find all internal hosts that have resolved or connected to this domain. Which search option should they use?
Select an answer first - 2
A Falcon Hunter is investigating a suspicious login from a specific user account on a particular host. The hunter wants to see all activity from that user account across the environment. Which search option is most appropriate?
Select an answer first - 3
A security analyst is investigating a potential command-and-control (C2) communication. The analyst has identified an external IP address that is believed to be the C2 server and wants to see which internal hosts have communicated with it. Which search option should the analyst use?
Select an answer first - 4
During an investigation, an analyst notices that multiple endpoints are communicating with a suspicious external IP address. The analyst wants to identify all affected assets. Which search option is most appropriate?
Select an answer first - 5
An analyst is investigating a phishing campaign that uses a large list of malicious domains. The analyst wants to check if any of these domains were accessed in the environment. Which search option is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.