
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 2
Determine Response Actions CCFR Practice Questions (Page 2)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
26questions here
6free pages
8concepts
Questions 6–10
- 6
A file has been quarantined by Falcon. The analyst has verified that the file is benign and was a false positive. What is the best practice for handling this quarantined file?
Select an answer first - 7
A security team wants to monitor for a suspicious file without preventing its execution, to observe its behavior in a controlled environment. Which hash management action should be used?
Select an answer first - 8
A company has a legitimate application that is being flagged by ML. The analyst wants to ensure the application runs without generating detections, but also wants to maintain visibility if the application is used maliciously. What is the best approach?
Select an answer first - 9
What is the effect of a machine learning exclusion rule in Falcon?
Select an answer first - 10
After a file is quarantined by Falcon, what is the first step an analyst should take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.