
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 5Objective 1
5.1 Use the Built-In Hunt Reports to Refine Event Details CCFH Practice Questions (Page 1)
Part of the Reports and References domain, which makes up ~8% of our current practice bank.
14questions here
3free pages
3concepts
Questions 1–5
- 1
An analyst is viewing a Hunt report and wants to see only events from a specific host. Which built-in option should they use?
Select an answer first - 2
A threat hunter is investigating a potential lateral movement attack. The hunter is using the 'Network Connections' Hunt report and needs to identify all connections from a compromised host (hostname 'SRV-001') to other internal hosts on port 445 (SMB). The report currently shows all network connections. The hunter wants to create a refined view that shows only these specific connections and also wants to see the process that initiated each connection. What is the most efficient approach?
Select an answer first - 3
A threat hunter is examining a Hunt report for 'Ransomware Indicators'. The report shows a list of events, but the hunter wants to see a summary of the most common file names that were flagged. What feature of the Hunt report should the hunter use to get this aggregated view?
Select an answer first - 4
A Hunt report shows a large number of events. The analyst wants to focus on events that occurred within the last 24 hours. Which built-in option should they use?
Select an answer first - 5
A security analyst is in the Falcon console and needs to access the built-in Hunt reports. Which menu option should they select?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.