
CrowdStrike Certified Falcon Responder (CCFR)
The CrowdStrike Certified Falcon Responder (CCFR) certification validates the skills of front-line security analysts who investigate and respond to detections in the CrowdStrike Falcon platform. It is designed for incident responders and anyone performing detection response duties, proving they can efficiently triage alerts, contain threats, and drive effective remediation. Earning CCFR demonstrates hands-on proficiency with Falcon's investigation and response workflows, making certified responders trusted operators in modern security operations centers.
528 practice questions · Updated 2026-07-30
CCFR Curriculum
Every domain, objective, and concept the CCFR exam measures.
- Purpose of MITRE ATT&CK
- Structure of ATT&CK
- Tactics
- Techniques and Sub-techniques
- Procedures
- Use Cases for Incident Response
- MITRE ATT&CK Framework Overview
- Mapping Detections to ATT&CK Tactics
- Mapping Detections to ATT&CK Techniques
- Using Falcon to Access ATT&CK Context
- Applying ATT&CK Context to Detection Analysis
- Falcon detection analysis workflow
- Activity dashboard interpretation
- Endpoint detections interpretation
- Contextual event data in detections
- Detection triage techniques
- Full Detection view analysis
- Process tree interpretation
- Process table interpretation
- Process activity interpretation
- Response Determination by Detection Source
- Built-in OSINT Tools Use Cases
- Impact of Internal and External Prevalence
- IOC and Falcon Actions
- Hash Management Actions
- Allowlisting and Blocklisting Effects
- Exclusion Rules Effects
- Quarantined File Best Practices
- Identify managed and unmanaged neighbors
- Understand neighbor context in Host Search
- Initiate Advanced Search from Detection
- Apply Search Filters and Conditions
- Use Event Actions for Refinement
- Interpret and Iterate on Search Results
- Identify event actions
- Determine appropriate event action
- Apply event actions
- Identify common event types
- Differentiate event types by purpose
- Map event types to detection scenarios
- Process Timeline Definition
- Timeline Data Sources
- Interpreting Timeline Events
- Process Relationships
- Timeline Visualization
- Use in Investigation
- Hosts Timeline overview
- Timeline event types
- Timeline filtering and search
- Interpreting event details
- Correlating events across the timeline
- Using timeline for investigation
- Event Search context
- Pivot to Process Timeline
- Pivot to Process Explorer
- Comparison of Process Timeline vs Process Explorer
- Process relationship types
- Reading process tree visualization
- Correlating process metadata
- Analyzing process behavior in context
- User Search Overview
- Search Parameters
- Interpreting Search Results
- User Activity Analysis
- Exporting and Sharing Results
- IP Search Overview
- Interpreting IP Search Results
- Analyzing IP Reputation and Threat Context
- Correlating IP Data with Other Falcon Data
- Hash Search Overview
- Interpreting Hash Search Results
- Using Hash Search for Investigation
- Host Search result fields
- Filtering and sorting Host Search results
- Interpreting host status indicators
- Correlating host data with other information
- Bulk Domain Search result fields
- Interpreting domain risk scores
- Correlating Bulk Domain Search data with other Falcon data
- Applying Bulk Domain Search results to incident response
- RTR Overview
- RTR Session Management
- RTR Command Execution
- RTR File Operations
- RTR Process and Service Management
- RTR Registry Operations
- RTR Scripting and Automation
- RTR Data Collection and Exfiltration
- RTR Host Isolation and Containment
- RTR Audit and Logging
- Administrative prerequisites
- RTR policy configuration
- Host and user scope
- Audit and compliance settings
- Host connection prerequisites
- Initiating an RTR session
- Selecting the appropriate connection method
- Handling connection failures and timeouts
- Session lifecycle management
- Threat Investigation Workflow
- Falcon Detection and Alert Analysis
- Host and Process Context
- RTR Command Fundamentals
- RTR File System Commands
- RTR Process and Service Commands
- RTR Registry and Persistence Commands
- RTR Network and Artifact Commands
- Remediation Strategy and Execution
- Verification and Post-Remediation Actions
- Custom script basics
- Script creation and upload
- Script execution in RTR
- Remediation techniques with scripts
- Script error handling and validation
- Security and permissions for scripts
- Understanding RTR custom scripts
- Creating a custom script
- Configuring script parameters
- Testing a custom script
- Setting up a workflow with RTR custom scripts
- Managing script versions and permissions
- Troubleshooting script execution
- Audit log overview
- Audit log event types
- Searching audit logs
- Interpreting audit log entries
- Correlating audit logs with RTR sessions
- Retaining and exporting audit logs
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCFR, so none is invented.