
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 1
Analyze the Information Provided in a User Search CCFR Practice Questions (Page 2)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
24questions here
5free pages
5concepts
Questions 6–10
- 6
A Falcon administrator is investigating a security incident and needs to find all users who have the email domain 'legacy.com' and are also members of the 'Legacy Users' group. Which search parameters should be used?
Select an answer first - 7
During a User Search review, an analyst sees that a user 'tnguyen' has logged into a device that is assigned to a different department and has also accessed files outside of their normal working hours. What should the analyst do first?
Select an answer first - 8
Which user activity pattern should a responder investigate further as a potential threat?
Select an answer first - 9
What is the purpose of the export feature in Falcon's User Search?
Select an answer first - 10
During a User Search investigation, an analyst notices that a user account 'mwilson' has an unusually high number of failed login attempts across multiple devices in a short time window, followed by a successful login from a device not previously associated with the user. Which conclusion is most appropriate based on this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.