
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 5Objective 2
5.2 Use the Built-In Visibility Reports to Refine Event Details CCFH Practice Questions (Page 2)
Part of the Reports and References domain, which makes up ~8% of our current practice bank.
15questions here
3free pages
5concepts
Questions 6–10
- 6
An analyst needs to see the specific command line arguments for a process event in a Visibility report. What should they do?
Select an answer first - 7
A threat hunter has finished refining a Network Connections report to show only TLS connections from a compromised server to a known command-and-control IP. The hunter needs to share this exact dataset with a colleague who does not have access to the Falcon console, so the colleague can perform independent analysis in a spreadsheet. Which action should the hunter take?
Select an answer first - 8
While reviewing a Visibility report, an analyst notices an unusual login event. What is the next step to investigate the event details further?
Select an answer first - 9
A security manager wants a high-level summary of the most common vulnerabilities affecting the organization's Windows servers, to prioritize patching efforts. The manager asks the analyst to produce this summary from a built-in Visibility report. Which report should the analyst use?
Select an answer first - 10
In a Visibility report, which filter would an analyst use to see events from a specific workstation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.