
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 6Objective 5
Utilize Custom Scripts in RTR to Remediate a Threat CCFR Practice Questions (Page 4)
Part of the Real Time Response (RTR) domain, which makes up ~34% of our current practice bank.
27questions here
6free pages
6concepts
Questions 16–20
- 16
What is the purpose of using a 'try/catch' block in an RTR custom script?
Select an answer first - 17
An analyst is writing a custom RTR script that will be run on a large number of hosts. The script must handle the case where a file to be deleted is locked by another process. The analyst wants the script to retry the deletion a few times before giving up. Which script structure should the analyst use?
Select an answer first - 18
What is a required step when uploading a custom script to the Falcon platform?
Select an answer first - 19
An analyst needs to write a custom script that will run on both Windows and Linux hosts via RTR. The script must check for a specific file and delete it if found. Which approach should the analyst take?
Select an answer first - 20
An analyst is executing a custom script via RTR that terminates a malicious process and deletes its associated files. The script runs successfully on the first host, but on the second host it fails with a 'permission denied' error. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.