
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 6Objective 4
Investigate a Threat Within Falcon and Use RTR Commands to Remediate It CCFR Practice Questions (Page 2)
Part of the Real Time Response (RTR) domain, which makes up ~34% of our current practice bank.
36questions here
8free pages
10concepts
Questions 6–10
- 6
What is the first step in developing a remediation plan using RTR commands?
Select an answer first - 7
What is the purpose of the RTR command 'reg delete'?
Select an answer first - 8
Which RTR command is used to list the contents of a directory on a compromised host?
Select an answer first - 9
What is the first step in the systematic threat investigation workflow within Falcon, from initial alert to containment?
Select an answer first - 10
A Falcon detection on a host shows a process making connections to a known malicious IP. You need to collect evidence of the network connections and any associated artifacts for further analysis. Which RTR command should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.