
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 3
Analyze the Information Provided in a Hash Search CCFR Practice Questions (Page 1)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
17questions here
4free pages
3concepts
Questions 1–5
- 1
You are investigating a host that has been beaconing to a known malicious IP. You find a file in the startup folder and run a Hash Search. The result is 'Suspicious' with low prevalence. What should you do NEXT?
Select an answer first - 2
During an incident investigation, an analyst finds a file hash and wants to determine if the file is known malicious. Which Falcon tool is most appropriate for this initial check?
Select an answer first - 3
A Falcon analyst needs to search for a file by its hash. Which of the following hash algorithms does the Hash Search tool in Falcon support?
Select an answer first - 4
A Hash Search on a file returns a 'Malicious' reputation, but the file is a signed Microsoft executable. You suspect a DLL side-loading attack. What is the MOST important next step to confirm this?
Select an answer first - 5
You have a hash from a third-party sandbox that is not in MD5, SHA1, or SHA256 format. Can you use Falcon's Hash Search to look it up?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.