
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 3Objective 1
Perform an Event Advanced Search from a Detection and Refine a Search Using Event Actions CCFR Practice Questions (Page 2)
Part of the Event Search domain, which makes up ~9% of our current practice bank.
18questions here
4free pages
4concepts
Questions 6–10
- 6
A Falcon Responder is investigating a detection on a domain controller. The detection details show a suspicious process, but the responder needs to determine if the process communicated with any external IP addresses. The responder pivots to an Event Advanced Search from the detection. What is the most effective way to identify external network communications?
Select an answer first - 7
An analyst is viewing a detection and wants to start an Event Advanced Search that includes the detection's associated process and network events. What is the most direct way to accomplish this?
Select an answer first - 8
While reviewing a detection in Falcon, an analyst wants to pivot into the underlying event data to investigate further. Which action should the analyst take directly from the detection's details?
Select an answer first - 9
After running an Event Advanced Search, an analyst sees a large number of results but notices that many are from a known benign application. What should the analyst do to focus on potentially malicious activity?
Select an answer first - 10
A detection is triggered on a workstation, and the Falcon Responder needs to investigate the parent process of the detected process. The detection details show the child process but not the parent. What is the most efficient way to find the parent process information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.