
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 2
Determine Response Actions CCFR Practice Questions (Page 3)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
26questions here
6free pages
8concepts
Questions 11–15
- 11
During an investigation, an analyst finds an IP address in a detection that is not in any internal logs. The analyst wants to quickly determine if this IP is known for malicious activity. Which built-in Falcon OSINT tool should the analyst use?
Select an answer first - 12
What is the effect of a sensor visibility exclusion in Falcon?
Select an answer first - 13
A detection is generated by an IOE (Indicator of Endpoint) rule that flags a suspicious file creation in a temp directory. The file is not seen elsewhere in the environment. What is the most appropriate response action?
Select an answer first - 14
An analyst is investigating a suspicious domain and wants to see if it has been associated with any known malware campaigns. Which Falcon built-in OSINT tool should be used for this enrichment?
Select an answer first - 15
What is an Indicator of Compromise (IOC) in the context of Falcon?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.