
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 6Objective 4
Investigate a Threat Within Falcon and Use RTR Commands to Remediate It CCFR Practice Questions (Page 5)
Part of the Real Time Response (RTR) domain, which makes up ~34% of our current practice bank.
36questions here
8free pages
10concepts
Questions 21–25
- 21
What does the RTR command 'cat' do when used on a file?
Select an answer first - 22
You are investigating a Falcon detection on a Windows host. The alert indicates a suspicious process running from a temp directory. You need to gather more context about the process and its parent before deciding on remediation. Which RTR command sequence should you use?
Select an answer first - 23
You are responding to a Falcon detection on a critical database server. The threat involves a malicious process and a scheduled task that recreates the process if it is killed. You need to remediate the threat without disrupting the database service. Which RTR command sequence should you use?
Select an answer first - 24
A Falcon detection on a Windows host shows a malicious service running under the SYSTEM account. The service has dependencies on other legitimate services. You need to stop the malicious service without affecting the legitimate services. Which RTR command should you use?
Select an answer first - 25
You are remediating a threat on a Windows host. The threat involves a malicious process, a scheduled task, and a file in the startup folder. You need to ensure all persistence mechanisms are removed. Which RTR command sequence should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.