
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 1
Analyze Detection Information CCFR Practice Questions (Page 3)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
33questions here
7free pages
9concepts
Questions 11–15
- 11
A Falcon administrator is reviewing the Endpoint detections list and sees hundreds of detections from the past 24 hours. The team has limited time to investigate and wants to focus on the most impactful threats first. The administrator needs to quickly identify detections that are both highly severe and actively spreading across multiple hosts. Which combination of filtering and sorting actions should the administrator use?
Select an answer first - 12
In the Endpoint security > Endpoint detections list, what does the 'Severity' column indicate?
Select an answer first - 13
A Falcon analyst is working through a detection that shows a single process making multiple outbound connections to different IP addresses on non-standard ports. The process is a known legitimate application that is used by the finance team. The analyst has verified the process hash is clean and the command line is typical. However, the detection is marked as 'High' severity. What is the most appropriate course of action?
Select an answer first - 14
A SOC lead is reviewing the Activity dashboard and notices that the 'Detections by Tactic' visualization shows a sudden increase in 'Credential Access' detections over the past hour. The 'Detections by Host' visualization shows that these detections are spread across 15 different hosts, all in the HR department. What is the most likely interpretation?
Select an answer first - 15
A Falcon analyst is reviewing the Endpoint detections list and sees a detection with a severity of 'Low' and a status of 'New'. The affected host is a test server that is not in production. The analyst has limited time and must prioritize. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.