
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 4Objective 2
Explain What Information a Hosts Timeline Will Provide CCFR Practice Questions (Page 5)
Part of the Event Investigation domain, which makes up ~14% of our current practice bank.
27questions here
6free pages
6concepts
Questions 21–25
- 21
A Falcon analyst is investigating a potential ransomware infection on a Windows host. The Hosts Timeline shows a large number of file write events to user directories, followed by a process execution that matches a known ransomware signature. The analyst needs to establish the timeline of compromise. What should the analyst do?
Select an answer first - 22
When viewing an individual event in the Hosts Timeline, what information is typically available?
Select an answer first - 23
Which of the following criteria can be used to filter the Hosts Timeline?
Select an answer first - 24
What is the primary value of correlating multiple events on the Hosts Timeline?
Select an answer first - 25
An incident responder is analyzing a Hosts Timeline for a compromised Linux host. The timeline shows a series of events: a user logs in via SSH, then a process is executed, then a file is written to /tmp, and then a network connection is made to an external IP. The responder needs to determine if the file write and network connection are related to the SSH login. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.