CrowdStrike Certified Falcon Hunter (CCFH) Free Practice Exam Questions

86 real CrowdStrike Certified Falcon Hunter (CCFH) exam questions with answers and AI explanations. CrowdStrike certification prep — page 2 of 9.

  1. Question 11: To find events that are outliers inside a network, ___________is the best hunting method to use.
  2. Question 12: What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
  3. Question 13: While you're reviewing Unresolved Detections in the Host Search page, you notice the User Name column contains “hostname$.” What does this User Name indicate?
  4. Question 14: With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of t…
  5. Question 15: What is the difference between a Host Search and a Host Timeline?
  6. Question 16: When reviewing a DNS request in the Event Search, you're curious which process made the request. Which Event Action would be the quickest way to show you the p…
  7. Question 17: You have found a hash-based indicator of compromise (IOC) in an intelligence report and want to determine if the program has run in your environment. Which sea…
  8. Question 18: What is the purpose of the rename command in this query? event_simpleName=ProcessRollup2 [search event_simpleName=ProcessRollup2 FileName=excel.exe | rename Ta…
  9. Question 19: What information is provided when using IP Search to look up an IP address?
  10. Question 20: Which field in a DNS Request event points to the responsible process?