
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 4Objective 4
Analyze Process Relationships (parent/child/sibling) Using the Information Contained in the Full Detection Details CCFR Practice Questions (Page 4)
Part of the Event Investigation domain, which makes up ~14% of our current practice bank.
17questions here
4free pages
4concepts
Questions 16–17
- 16
In the Full Detection Details, a process tree shows that a Microsoft Word document spawned a PowerShell process, which then spawned a cmd.exe process. What does this sequence suggest about the nature of the activity?
Select an answer first - 17
In the Full Detection Details, a process tree shows that a legitimate system process (e.g., svchost.exe) spawned an unknown executable from a temporary folder. What does this context suggest?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.