
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 5
Analyze the Information Provided in a Bulk Domain Search CCFR Practice Questions (Page 1)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
24questions here
5free pages
4concepts
Questions 1–5
- 1
A Bulk Domain Search result for 'cdn-fast.net' shows a risk score of 30 and an associated indicator of 'none'. The domain is used by a legitimate CDN service. The analyst is investigating a malware outbreak and wants to rule out this domain. What should the analyst do?
Select an answer first - 2
During incident response, an analyst runs a Bulk Domain Search on a list of domains extracted from a compromised host's DNS cache. One domain has a risk score of 95 and is associated with a known C2 framework. The analyst needs to determine the scope of the incident. What should the analyst do next?
Select an answer first - 3
An analyst reviews a Bulk Domain Search result for 'legit-site.com'. The result shows the domain name, a risk score of 20, and an associated indicator of 'phishing'. The domain is a well-known legitimate service. How should the analyst interpret this result?
Select an answer first - 4
While reviewing Bulk Domain Search results, a responder sees a domain listed along with several file hashes and IP addresses. What are these additional items called in the context of the search results?
Select an answer first - 5
During an incident, an analyst identifies a high-risk domain from Bulk Domain Search that is associated with a C2 server. The analyst needs to contain the threat. What should the analyst do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.