
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 2Objective 2
Determine Response Actions CCFR Practice Questions (Page 5)
Part of the Detection Analysis domain, which makes up ~14% of our current practice bank.
26questions here
6free pages
8concepts
Questions 21–25
- 21
An analyst is investigating a detection that involves a domain that is not in any internal logs. The domain has low external prevalence, but the analyst wants to determine if it is malicious. The analyst has limited time and needs to make a quick decision. What is the best use of Falcon's built-in OSINT tools?
Select an answer first - 22
A file hash is found on many hosts across the customer's environment, but it is not reported in any external threat intelligence sources. What is the most appropriate response consideration?
Select an answer first - 23
A detection is triggered for a file that is present on 80% of the organization's hosts. External prevalence is high, and the file is signed by a reputable vendor. The file is flagged by ML as suspicious. What is the best response action?
Select an answer first - 24
A company has a critical application that is being flagged by ML. The application is signed by a reputable vendor and is used by all employees. The analyst wants to ensure the application runs without generating detections, but also wants to maintain visibility if the application is used maliciously. What is the best approach?
Select an answer first - 25
What is a recommended remediation step after confirming a quarantined file is malicious?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.