CrowdStrike Certified Falcon Responder (CCFR) Free Practice Exam Questions

59 real CrowdStrike Certified Falcon Responder (CCFR) exam questions with answers and AI explanations. CrowdStrike certification prep — page 2 of 6.

  1. Question 11: After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
  2. Question 12: You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
  3. Question 13: The function of Machine Learning Exclusions is to _____________.
  4. Question 14: What information does the MITRE ATT&CK Framework provide?
  5. Question 15: Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?
  6. Question 16: How long does detection data remain in the CrowdStrike Cloud before purging begins?
  7. Question 17: What action is used when you want to save a prevention hash for later use?
  8. Question 18: You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service w…
  9. Question 19: In the Hash Search tool, which of the following is listed under Process Executions?
  10. Question 20: What is the difference between a Host Search and a Host Timeline?