
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 6Objective 7
Review Audit Logs to Audit RTR Activity CCFR Practice Questions (Page 1)
Part of the Real Time Response (RTR) domain, which makes up ~34% of our current practice bank.
24questions here
5free pages
6concepts
Questions 1–5
- 1
An analyst is correlating audit log entries with RTR sessions and finds that a session ID appears in the audit logs, but the session is not listed in the RTR session list. What is the most likely explanation?
Select an answer first - 2
Which method can be used to export RTR audit log data for external analysis?
Select an answer first - 3
Which of the following RTR activities would be recorded as an audit log event?
Select an answer first - 4
A company is required to retain RTR audit logs for 7 years due to regulatory requirements. The Falcon console's default retention is only 90 days. The company has a SIEM with limited storage and cannot store all logs for 7 years. Which approach best balances compliance and storage constraints?
Select an answer first - 5
An analyst is reviewing an audit log entry and sees the field `actor` with the value `user@company.com`. The analyst needs to confirm whether this user is a Falcon admin or a standard user. Which additional field in the audit log entry would provide this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.