
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 3
Analyze the Information Provided in a Hash Search CCFR Practice Questions (Page 3)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
17questions here
4free pages
3concepts
Questions 11–15
- 11
An analyst performs a Hash Search on a file and sees that the result indicates a 'malicious' reputation with high prevalence. What does the 'prevalence' value in the Hash Search results represent?
Select an answer first - 12
Your Hash Search for a file returns a reputation of 'Unknown' and a prevalence score of 0. The file is found in a temporary directory on a user's workstation. What is the MOST appropriate conclusion?
Select an answer first - 13
You are investigating a potential supply-chain attack. A Hash Search on a signed executable from a trusted vendor returns a 'Malicious' reputation. The file is signed with a valid certificate, and the prevalence is low. Your CISO is skeptical and wants to know if this is a real threat. What is the MOST compelling evidence from the Hash Search results to support the finding?
Select an answer first - 14
You are analyzing a file that has a 'Malicious' reputation and a prevalence score of 1. The file is a DLL that is loaded by a legitimate, signed executable. What does the low prevalence score MOST likely suggest about the attack?
Select an answer first - 15
You are investigating a potential data exfiltration incident. A Hash Search on a file found on a compromised host returns a 'Suspicious' reputation with low prevalence. What is the MOST appropriate next step to determine if this file is related to the incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.