Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 3Objective 3

Distinguish Between Commonly Used Event Types CCFR Practice Questions (Page 3)

Part of the Event Search domain, which makes up ~9% of our current practice bank.

19questions here
4free pages
3concepts

Questions 11–15

  1. 11foundation · easy

    An analyst is investigating a potential command-and-control (C2) communication. Which event type would be most appropriate to search for DNS queries to a known malicious domain?

    Select an answer first
  2. 12application · medium

    A security analyst is investigating a malware infection where the malware is suspected of modifying the hosts file to redirect traffic. The analyst needs to identify when the hosts file was modified. Which event type should be queried?

    Select an answer first
  3. 13foundation · easy

    What is the primary purpose of the NetworkConnectIP4 event type in Falcon Event Search?

    Select an answer first
  4. 14application · medium

    A Falcon administrator is reviewing an alert where a process attempted to connect to a known command-and-control (C2) server. The administrator wants to confirm the connection attempt and identify the process responsible. Which event types should be combined in the search?

    Select an answer first
  5. 15expert · hard

    A security analyst is investigating a ransomware attack where the malware encrypted files and then deleted the original files. The analyst needs to identify both the encryption and deletion activities. Which event types should be combined in the search to capture both activities?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.