Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

CCFR-201b Questions and Answers

Question # 6

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?

A.

ParentProcessld_decimal and aid

B.

ResponsibleProcessld_decimal and aid

C.

ContextProcessld_decimal and aid

D.

TargetProcessld_decimal and aid

Full Access
Question # 7

Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:

root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.

Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?

A.

Remote exploitation of a system service

B.

User execution via a Phishing email or drive-by download

C.

Malicious persistence via a WMI event subscription

D.

Credential theft through a compromised Domain Controller

Full Access
Question # 8

The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?

A.

500

B.

750

C.

1000

D.

1200

Full Access
Question # 9

Depending on the subscription level, " Cloudable Events " (standard telemetry) have a specific retention period. What is the minimum period of time that these events are retained?

A.

1 day

B.

7 days

C.

14 days

D.

30 days

Full Access
Question # 10

The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?

A.

Activity

B.

Investigate

C.

Configuration

D.

Dashboards

Full Access
Question # 11

Refer to the image.

Question # 11

What does the arrowed line indicate?

A.

PowerShell spawned Notepad.exe, which injected a thread back to Excel.exe

B.

The thread injection was considered a Medium severity injection

C.

PowerShell spawned Notepad.exe, which injected a thread back to PowerShell

D.

Notepad.exe injected itself into Excel.exe

Full Access
Question # 12

The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?

A.

The Process Activity View creates a consolidated view of all detection events for that process that can be exported for further analysis

B.

The Process Activity View will show the Detection time of the earliest recorded activity which might indicate first affected machine

C.

The Process Activity View only creates a summary of Dynamic Link Libraries (DLLs) loaded by a process

D.

The Process Activity View creates a count of event types only, which can be useful when scoping the event

Full Access
Question # 13

In the Falcon Overwatch Best Practice workflow, at what specific point is a responder encouraged to utilize OSINT (Open Source Intelligence) searches?

A.

During the ' Understand the detection ' phase.

B.

During the ' Understand process(es) involved ' phase.

C.

During the ' Examine what is normal for the system ' phase.

D.

After the incident has been fully remediated.

Full Access
Question # 14

While examining the ' Process Details ' sidebar of a detection, a responder sees the following icons: " 25 Network Operations " and " 277 Disk Operations " . What does this contextual data represent?

A.

The percentage of the CPU being consumed by the network and disk.

B.

The specific number of telemetry events recorded for network and disk activity by that process.

C.

The total size in megabytes of the data sent over the network and written to disk.

D.

The number of other hosts that have seen similar network and disk activity.

Full Access
Question # 15

When investigating system-level persistence, it is critical to know what the services.exe process is responsible for. What is its primary function?

A.

Managing user profiles and registry hives during login.

B.

Launching and managing the lifecycle of system services.

C.

Monitoring network traffic for potential data exfiltration.

D.

Providing a graphical interface for the Windows Task Manager.

Full Access
Question # 16

An analyst needs to perform local sandbox analysis on a malicious file. When they download a quarantined file from the Falcon UI, what is the file format and the default password?

A.

.zip, password: crowdstrike

B.

.7-zip, password: infected

C.

.rar, password: malware

D.

.exe, no password

Full Access
Question # 17

While quarantined files stay on the local host for 30 days by default, how many days does a quarantined file remain stored in the CrowdStrike Cloud?

A.

30 days

B.

60 days

C.

90 days

D.

180 days

Full Access
Question # 18

Which Executive Summary dashboard item indicates sensors running with unsupported versions?

A.

Detections by Severity

B.

Inactive Sensors

C.

Sensors in RFM

D.

Active Sensors

Full Access
Question # 19

When managing files within the ' Quarantined Files ' dashboard, which of the following is NOT a valid action available to the responder?

A.

Release

B.

Download

C.

Investigate

D.

Delete

Full Access
Question # 20

A responder releases a file from quarantine on a specific workstation. What is the default scope of the allowlist that is created during this process?

A.

Global (applies to all hosts in the environment)

B.

Only the specific host where the file was originally quarantined

C.

All hosts within the same host group as the source host

D.

All hosts running the same operating system version

Full Access
Question # 21

When navigating the ' Custom IOA ' creation wizard, a user must select a rule type. Which of the following is NOT a valid IOA rule type available for selection?

A.

Process Creation

B.

File Creation

C.

Domain Name

D.

Scheduled Task

Full Access
Question # 22

While investigating a detection, you pivot to the Advanced Event Search.

Which field would you filter by to return events executing from a specific directory on the host?

A.

TreeId

B.

@source

C.

ParentBaseFileName

D.

FilePath

Full Access
Question # 23

A responder is using ' Host Search ' to gather baseline data on a machine. Which of the following pieces of information is NOT provided by the Host Search results?

A.

List of running services and drivers.

B.

Macro Execution History for Microsoft Office products.

C.

Recent network connections and IP addresses.

D.

List of local user accounts and administrators.

Full Access
Question # 24

When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?

A.

Do nothing, as this file is common and well known

B.

From detection, click the VT Hash button to pivot to VirusTotal to investigate further

C.

From detection, use API manager to create a custom blocklist

D.

From detection, submit to FalconX for deep dive analysis

Full Access
Question # 25

What is the difference between Managed and Unmanaged Neighbors in the Falcon console?

A.

A managed neighbor is currently network contained and an unmanaged neighbor is uncontained

B.

A managed neighbor has an installed and provisioned sensor

C.

An unmanaged neighbor is in a segmented area of the network

D.

A managed sensor has an active prevention policy

Full Access
Question # 26

To track the relationship between a parent and its child, Falcon uses specific ID fields. What raw data is used as the ' ParentProcessId_decimal ' when a process spawns a child process?

A.

The Operating System PID of the parent.

B.

The TargetProcessId_decimal of the parent process.

C.

The ContextProcessId_decimal of the system.

D.

The RootProcessId_decimal of the entire tree.

Full Access
Question # 27

When viewing the summary list on the ' Endpoint Detections ' page, an analyst sees a column for the timestamp. What does the timestamp in this specific summary view represent?

A.

The exact time the Falcon sensor was first installed on the host.

B.

The timestamp of the last activity recorded for that specific detection.

C.

The time the detection was first assigned to a human analyst.

D.

The file creation time for the primary process involved in the alert.

Full Access
Question # 28

Which is TRUE regarding a file released from quarantine?

A.

No executions are allowed for 14 days after release

B.

It is allowed to execute on all hosts

C.

It is deleted

D.

It will not generate future machine learning detections on the associated host

Full Access
Question # 29

A responder is analyzing a MITRE-related alert and sees the technique ' Explore > Discovery > Cloud Service Dashboard ' . Which of the following scenarios best describes the technical activity associated with this technique?

A.

An adversary uses an automated script to bruteforce S3 bucket permissions.

B.

An adversary uses a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment.

C.

An adversary executes an API call to terminate all running EC2 instances in a region.

D.

An adversary deploys a crypto-miner inside a compromised Docker container.

Full Access
Question # 30

In the ' Graph View ' of a detection, processes are connected by arrows. Which of the following does a yellow arrow connecting two processes indicate?

A.

A standard Parent-Child relationship.

B.

A Network connection was established between the two processes.

C.

A Thread Injector-Injectee relationship (Process Injection).

D.

A file was written by the first process and read by the second.

Full Access
Question # 31

If a local administrator needs to inspect the quarantine directory directly on a machine, where are quarantine files located on a Windows Endpoint?

A.

C:\Temp\CrowdStrike\Quarantine

B.

C:\Windows\System32\Drivers\CrowdStrike\Quarantine

C.

C:\Program Files\CrowdStrike\Quarantine

D.

C:\Users\Public\CrowdStrike\Quarantine

Full Access
Question # 32

Which of the following subtitles/sub-views cannot be seen in the results of a ' Hash Search ' ?

A.

File Metadata

B.

Process Timeline

C.

Intel Indicators

D.

Execution History

Full Access
Question # 33

An attacker attaches cmd.exe as a debugger to osk.exe through a registry key.

What tactic and technique describe this activity?

A.

Persistence via Image File Execution Options Injection

B.

Post-Exploit via Malicious Tool Execution

C.

Persistence via External Remote Services

D.

Privilege Escalation via Bypass User Account Control

Full Access
Question # 34

When reviewing CrowdScore Incidents, which of the following statements is INCORRECT?

A.

Incidents aggregate related detections to reduce alert fatigue.

B.

Incidents are defined as inactive after 10 hours pass without any new related activity.

C.

A high CrowdScore indicates a higher likelihood of a sophisticated or widespread attack.

D.

CrowdScore is only visible to users with the ' Falcon Administrator ' role.

Full Access
Question # 35

Which of the following sentences best describes the technical visibility provided by the ' Host Timeline ' view?

A.

A list of every time a user has logged in or out of the machine.

B.

Every host-relevant event (Process, File, Registry, Network) recorded in a given timeframe.

C.

A history of every hardware change or driver update on the endpoint.

D.

A log of every time the Falcon sensor was updated or restarted.

Full Access
Question # 36

An analyst needs to quickly view the activity surrounding a suspicious process. Which of the following sequences of steps will pivot to an auto-filled process timeline in the Falcon UI?

A.

Host Search > Processes and Services > Filename > Start Time > Process ID

B.

Activity Dashboard > Click Detection > Export to PDF

C.

Investigate > Bulk Search > Enter SHA256 > View Results

D.

Configuration > Host Groups > Select Host > Network History

Full Access
Question # 37

What is an advantage of using a Process Timeline?

A.

Process related events can be filtered to display specific event types

B.

Suspicious processes are color-coded based on their frequency and legitimacy over time

C.

Processes responsible for spikes in CPU performance are displayed overtime

D.

A visual representation of Parent-Child and Sibling process relationships is provided

Full Access
Question # 38

When an analyst is trying to pinpoint the exact moment an endpoint came online after being shut down for the weekend, which timeline view is the best to use?

A.

Process Timeline

B.

Host Timeline

C.

User Timeline

D.

Network Timeline

Full Access
Question # 39

When using ' User Search ' to investigate a potentially compromised account, which of the following is NOT a filter available in the User Search?

A.

Username

B.

Hostname

C.

Process ID

D.

Time Range

Full Access
Question # 40

CrowdStrike supports various deployment types. What is a ' POD sensor ' ?

A.

A sensor specifically designed for mobile devices (iOS/Android).

B.

A sensor that is installed directly on a Kubernetes or Docker host to monitor containers.

C.

A legacy sensor used only for disconnected or air-gapped systems.

D.

A physical appliance that sits on the network to monitor traffic.

Full Access
Question # 41

Which of the following is an example of a MITRE ATT AND CK tactic?

A.

Eternal Blue

B.

Defense Evasion

C.

Emotet

D.

Phishing

Full Access
Question # 42

How does a DNSRequest event link to its responsible process?

A.

Via both its ContextProcessld__decimal and ParentProcessld_decimal fields

B.

Via its ParentProcessld_decimal field

C.

Via its ContextProcessld_decimal field

D.

Via its TargetProcessld_decimal field

Full Access
Question # 43

CrowdStrike provides ' Overwatch Best Practices ' for triaging alerts. According to these guidelines, what is the next step a responder should take immediately after the ' Understand the detection ' step?

A.

Isolate the host from the network.

B.

Review the process tree to understand the origin of the activity.

C.

Perform an OSINT search for the suspicious hash.

D.

Resolve the detection as a True Positive.

Full Access
Question # 44

A responder is analyzing a file ' s prevalence. If the data shows ' Local: High ' and ' Global: Unique ' , which of the following is the most likely conclusion?

A.

The file is common off-the-shelf malware seen globally.

B.

The file is internally developed software unique to the organization.

C.

The file is a standard Windows system component.

D.

The file is a known commodity tool used by many different actors.

Full Access
Question # 45

Where are quarantined files stored on Windows hosts?

A.

Windows\Quarantine

B.

Windows\System32\Drivers\CrowdStrike\Quarantine

C.

Windows\System32\

D.

Windows\temp\Drivers\CrowdStrike\Quarantine

Full Access
Question # 46

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

A.

Identifies a detailed list of all process executions for the specified hashes

B.

Identifies hosts that loaded or executed the specified hashes

C.

Identifies users associated with the specified hashes

D.

Identifies detections related to the specified hashes

Full Access
Question # 47

A responder is focused on a specific malicious script and wants to see everything that the script ' s process did. Which timeline is the best tool for this task?

A.

Host Timeline

B.

Process Timeline

C.

User Timeline

D.

Administrative Timeline

Full Access
Question # 48

Which of the following sentences best describes the primary objective of ' Real-time Analysis ' within the Falcon platform?

A.

Analyzing historical logs from the past 90 days to find missed threats.

B.

Investigating incoming telemetry in real time or on a near real-time basis to catch active threats.

C.

Scanning every file on a hard drive once per week for dormant viruses.

D.

Manually updating the Falcon sensor on every machine in the fleet.

Full Access
Question # 49

A responder is explaining the quarantine process to a system administrator. What happens technically when a file is quarantined by the Falcon sensor?

A.

It is deleted from the disk and a log is sent to the cloud.

B.

It is moved to the CrowdStrike Cloud and removed from the local host immediately.

C.

It is compressed, password protected, and moved to the Quarantine folder on the endpoint.

D.

It is renamed to a .tmp extension and moved to the Windows Recycle Bin.

Full Access
Question # 50

After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?

A.

Draw Process Explorer

B.

Show a +/- 10-minute window of events

C.

Show a Process Timeline for the responsible process

D.

Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)

Full Access
Question # 51

The User Search results are organized into several categories. Which of the following is NOT a sub-heading in the User Search?

A.

User Logons

B.

Unique Executables Written

C.

Admin tool usage

D.

Network Connections

Full Access
Question # 52

Which of the following is NOT a filter available on the Detections page?

A.

Severity

B.

CrowdScore

C.

Time

D.

Triggering File

Full Access
Question # 53

After an investigation, the following malicious artifacts have been identified:

    C:\Users*\AppData\iamnotmalware.exe

    C:\Users*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iamnotmalware.lnk

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iamnotmalware_really

What method will remove all associated artifacts from hosts that trigger future related detections?

A.

Create a Quarantine Rule that will quarantine all identified artifacts across the entire environment

B.

Create Custom IOA rules to prevent the execution of these artifacts

C.

Create a workflow to trigger on a new endpoint detection, query the telemetry data of the endpoint for known artifacts, and select Remove All Associated Artifacts as an action

D.

Create a workflow to trigger on a new endpoint detection, conditions that match the detection, and as an action a PowerShell script to kill associated processes and remove all artifacts

Full Access
Question # 54

Filtering is essential for managing a high volume of alerts. Which of the following filters is available by default within the ' Endpoint Detections ' dashboard to help narrow down specific threats?

A.

Triggering File

B.

Hardware BIOS Version

C.

Local Subnet Mask

D.

Sensor Update Policy Name

Full Access
Question # 55

Responders must understand the limitations and capabilities of custom rules. Which of the following statements about custom IOAs is FALSE?

A.

They can be used to monitor or block specific command-line strings.

B.

A Custom IOA rule group can only be applied to one single prevention policy.

C.

They can generate ' Informational ' detections if set to the ' Monitor ' action.

D.

They allow for pattern matching using wildcards or specific strings.

Full Access
Question # 56

You have a folder with the path C:\Windows\BadTools.

Using native Real Time Response (RTR) commands, what is the correct syntax to remove the folder and all of its contents?

A.

remove " C:\Windows\BadTools " -all

B.

rm " C:\Windows\BadTools " -force

C.

rm " C:\Windows\BadTools " -rf

D.

remove " C:\Windows\BadTools " -f

Full Access
Question # 57

Refer to the image.

Question # 57

You receive the detection displayed in the image above on a host in your environment.

Assuming you have the correct permissions, where would you navigate to remotely connect to the host and investigate further?

A.

Investigate > Connect to host

B.

View Incident > Connect to host

C.

Actions > Connect to host

Full Access
Question # 58

Executive dashboards provide a high-level view of security. Which of the following CANNOT be seen from the Executive Summary Dashboard?

A.

Detections broken down by Tactic.

B.

A breakdown of Agent Versions across the fleet.

C.

The top 10 hosts with the most detections.

D.

The organization’s current CrowdScore trend.

Full Access
Question # 59

During the incident response process, a responder must update the status of a detection. Which of the following options is NOT a valid detection status recognized by the Falcon console?

A.

New

B.

Complete

C.

In Progress

D.

True Positive

Full Access
Question # 60

An executive asks for a definition of ' CrowdScore ' . Which of the following sentences best describes what CrowdScore is?

A.

It is a ranking system that compares your organization’s security to other companies.

B.

It is a metric designed to show an organization ' s threat level on a continual basis by aggregating related detections.

C.

It is the total number of detections that have been resolved within the last 24 hours.

D.

It is a measure of the total processing power being used by the Falcon sensors globally.

Full Access
Question # 61

You are concerned that a compromised user may have run multiple malicious commands across multiple hosts.

What information from Investigate > Search > Users will help you quickly find evidence of this behavior?

A.

Detect history

B.

User logon activities

C.

File-transfer port activities

D.

Admin tool usage

Full Access
Question # 62

During the configuration of a new IOA rule, the administrator must decide what action the sensor should take. Which of the following is NOT a valid IOA rule action?

A.

Monitor

B.

Block

C.

No Action

D.

Kill Process

Full Access