
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 2
Determine Response Actions CCFR Practice Questions (Page 4)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
26questions here
6free pages
8concepts
Questions 16–20
- 16
An analyst is investigating a detection for a file that is not malicious but is causing false positives. The file is a custom internal tool used by the engineering team. The analyst wants to stop the false positives while still allowing the tool to run. What is the best hash management action?
Select an answer first - 17
Which of the following is an example of an action that can be taken on an IOC in Falcon?
Select an answer first - 18
An analyst wants to prevent a known malicious file from executing on any host in the environment, but they do not want to hide the detection from the security team. Which hash management action should be used?
Select an answer first - 19
A detection is generated by Falcon's machine learning (ML) engine because a file exhibits malicious characteristics. What is the primary response action for this type of detection?
Select an answer first - 20
An analyst notices that a specific legitimate application is being flagged by ML detections. The analyst wants to stop the false positives without affecting detections for other files. What type of exclusion rule should be created?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.