
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 4Objective 4
Analyze Process Relationships (parent/child/sibling) Using the Information Contained in the Full Detection Details CCFR Practice Questions (Page 2)
Part of the Event Investigation domain, which makes up ~14% of our current practice bank.
17questions here
4free pages
4concepts
Questions 6–10
- 6
You are investigating a detection where the process tree shows 'svchost.exe' (PID 700) spawning 'dllhost.exe' (PID 800). The command line of dllhost.exe includes a reference to a COM object. You also notice that svchost.exe (PID 700) was spawned by 'services.exe' (PID 500). What is the most accurate description of the process tree?
Select an answer first - 7
In the Full Detection Details of the Falcon console, a process is shown as a direct child of another process. What does this relationship indicate?
Select an answer first - 8
In the process tree visualization of the Full Detection Details, what does the topmost node typically represent?
Select an answer first - 9
During an investigation, you find a process 'msiexec.exe' with PID 1234 and PPID 5678. The process with PID 5678 is 'explorer.exe'. However, the command line of msiexec.exe shows it was launched from a temporary directory. What does this combination of metadata suggest?
Select an answer first - 10
You are reviewing a detection where the process tree shows 'explorer.exe' (PID 1000) with two children: 'cmd.exe' (PID 2000) and 'rundll32.exe' (PID 2001). Both child processes have the same parent PID. What does this structure indicate about the relationship between cmd.exe and rundll32.exe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.