
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 1
Analyze Detection Information CCFR Practice Questions (Page 5)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
33questions here
7free pages
9concepts
Questions 21–25
- 21
A Falcon analyst opens a detection triggered by a suspicious PowerShell command on a finance workstation. The Process Tree view shows powershell.exe spawned by winword.exe, which was launched from an email attachment. The PowerShell process then spawned cmd.exe, which executed a script that made an outbound connection to an IP address not seen before in the environment. Which conclusion is best supported by this process tree?
Select an answer first - 22
In the Endpoint security > Activity dashboard, which metric is used to identify a sudden spike in endpoint activity that may indicate an anomaly?
Select an answer first - 23
An analyst is following the Falcon detection analysis workflow for a new detection. The analyst has already reviewed the detection details, examined the process tree, and identified the malicious activity. According to the workflow, what is the next step the analyst should take?
Select an answer first - 24
A Falcon Responder wants to focus on the most critical detections first. Which triage technique is most appropriate?
Select an answer first - 25
In the Endpoint security > Endpoint detections list, what does the 'Status' column typically show?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.