
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 6Objective 4
Investigate a Threat Within Falcon and Use RTR Commands to Remediate It CCFR Practice Questions (Page 1)
Part of the Real Time Response (RTR) domain, which makes up ~34% of our current practice bank.
36questions here
8free pages
10concepts
Questions 1–5
- 1
What is a common post-remediation action to ensure the host is secure?
Select an answer first - 2
A Falcon alert on a web server shows a process making outbound connections to a known C2 domain. The process is a legitimate-looking service binary. You need to determine if the binary is malicious or if it has been tampered with, and you must preserve evidence for potential legal action. Which approach should you take?
Select an answer first - 3
After executing a remediation plan, what is the purpose of verification?
Select an answer first - 4
A Falcon detection on a Windows host shows a process running from a user's AppData folder. The process has a valid digital signature from a known software vendor. You need to determine if this is a false positive or a legitimate threat. Which RTR command sequence should you use?
Select an answer first - 5
What is the purpose of the RTR command 'kill'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.