Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 3Objective 3

Distinguish Between Commonly Used Event Types CCFR Practice Questions (Page 1)

Part of the Event Search domain, which makes up ~9% of our current practice bank.

19questions here
4free pages
3concepts

Questions 1–5

  1. 1application · medium

    A security analyst is investigating a malware infection where the malware is suspected of making DNS queries to a dynamic DNS service to locate its C2 server. The analyst needs to identify the DNS queries made by the malware. Which event type should be queried?

    Select an answer first
  2. 2foundation · easy

    Which Falcon Event Search event type is used to capture the execution of a new process on an endpoint?

    Select an answer first
  3. 3foundation · easy

    An analyst needs to identify all processes that were executed on a host during a specific time window. Which event type should be used in the search?

    Select an answer first
  4. 4application · medium

    A Falcon administrator is analyzing an alert where a process spawned a child process that then made a DNS query to a known malicious domain. The administrator wants to correlate the parent process with the DNS query. Which event types should be combined in the search?

    Select an answer first
  5. 5application · medium

    A threat hunter is investigating a supply chain attack where a legitimate software update was modified to include malicious code. The hunter needs to identify when the malicious file was written to disk. Which event type should be queried?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.