
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 4Objective 4
Analyze Process Relationships (parent/child/sibling) Using the Information Contained in the Full Detection Details CCFR Practice Questions (Page 3)
Part of the Event Investigation domain, which makes up ~14% of our current practice bank.
17questions here
4free pages
4concepts
Questions 11–15
- 11
In the Full Detection Details, which metadata field is used to identify the parent of a given process?
Select an answer first - 12
You are investigating a detection where the process tree shows 'powershell.exe' (PID 2000, PPID 1500) spawning 'cmd.exe' (PID 2100). The process with PID 1500 is 'explorer.exe'. However, the command line of powershell.exe shows it was launched with '-EncodedCommand'. You also notice that 'cmd.exe' (PID 2100) spawned 'whoami.exe' (PID 2200). What is the most significant indicator of malicious activity in this chain?
Select an answer first - 13
In the Full Detection Details, which piece of process metadata is most useful for understanding what arguments were passed to a process when it was launched?
Select an answer first - 14
You are reviewing a detection where the process tree shows 'wscript.exe' (PID 1000) spawning 'cmd.exe' (PID 1100), which then spawned 'powershell.exe' (PID 1200). The command line of wscript.exe includes a reference to a .vbs file in the user's Downloads folder. What is the most likely interpretation of this process chain?
Select an answer first - 15
When reading the process tree in the Full Detection Details, what does a branch from a parent node to multiple child nodes indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.