Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 2Objective 2

Determine Response Actions CCFR Practice Questions (Page 3)

Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.

26questions here
6free pages
8concepts

Questions 11–15

  1. 11application · medium

    During an investigation, an analyst finds an IP address in a detection that is not in any internal logs. The analyst wants to quickly determine if this IP is known for malicious activity. Which built-in Falcon OSINT tool should the analyst use?

    Select an answer first
  2. 12foundation · easy

    What is the effect of a sensor visibility exclusion in Falcon?

    Select an answer first
  3. 13application · medium

    A detection is generated by an IOE (Indicator of Endpoint) rule that flags a suspicious file creation in a temp directory. The file is not seen elsewhere in the environment. What is the most appropriate response action?

    Select an answer first
  4. 14foundation · easy

    An analyst is investigating a suspicious domain and wants to see if it has been associated with any known malware campaigns. Which Falcon built-in OSINT tool should be used for this enrichment?

    Select an answer first
  5. 15foundation · easy

    What is an Indicator of Compromise (IOC) in the context of Falcon?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.