
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 5Objective 2
Analyze the Information Provided in an IP Search CCFR Practice Questions (Page 2)
Part of the Search Tools domain, which makes up ~19% of our current practice bank.
16questions here
4free pages
4concepts
Questions 6–10
- 6
During an incident investigation, an analyst finds a suspicious IP in IP Search and wants to see if any hosts in the environment have executed files associated with that IP. Which Falcon data source should the analyst correlate with the IP Search results?
Select an answer first - 7
An IP Search for 203.0.113.88 shows it is associated with a host that has a detection for a known malware family. The Responder wants to determine if the malware is still active on the host. Which Falcon data should the Responder correlate with the IP Search results?
Select an answer first - 8
When analyzing the reputation of an IP address in Falcon, what does a 'malicious' reputation indicate?
Select an answer first - 9
An IP Search for 203.0.113.150 returns a threat score of 10, but the IP is associated with a domain that has been flagged for phishing. The Responder must decide whether to include this IP in an IOC blocklist. What is the most appropriate action?
Select an answer first - 10
A Responder is investigating a potential data exfiltration incident. An IP Search for 203.0.113.55 shows a threat score of 70 and an association with a domain known for data theft. However, the IP is also used by a major cloud storage provider. The Responder must decide whether to block the IP. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.