
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 2
Analyze the Information Provided in an IP Search CCFR Practice Questions (Page 1)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
16questions here
4free pages
4concepts
Questions 1–5
- 1
A Responder is reviewing an IP Search for 203.0.113.200. The IP has a threat score of 75 and is associated with a domain that has a history of hosting malware. However, the IP is also used by a legitimate cloud service provider. What should the Responder conclude from this information?
Select an answer first - 2
An analyst runs an IP Search and sees that a particular IP address is associated with multiple hosts in the environment. What does this association indicate?
Select an answer first - 3
During an incident, a Responder finds that an IP Search for 198.51.100.44 shows it is associated with a host that has a detection for credential dumping. The Responder wants to determine if the IP is part of a larger campaign. Which Falcon feature should the Responder use to look for other hosts that may have communicated with this IP?
Select an answer first - 4
When reviewing IP Search results for a suspicious address, which type of data would an analyst expect to see in the results?
Select an answer first - 5
An IP Search result shows an IP address with a 'suspicious' reputation. What should an analyst infer from this label?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.