Exam style questions across every CCFR-201b domain
Last Update 4 days ago
Total Questions : 209
Start with our free CCFR-201b practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CCFR exam. Each CCFR-201b exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your CrowdStrike weak domains, see where you're losing marks, and build a focused study plan in minutes.
CrowdScore is a metric used to identify the severity of an ongoing incident. What percentage of increase in a CrowdScore is considered a strong indication of a coordinated attack?
An analyst wants to see the raw events behind a specific detection. Which icon in the UI allows them to pivot directly to an event search?
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
When using ' User Search ' to investigate a potentially compromised account, which of the following is NOT a filter available in the User Search?
To track the relationship between a parent and its child, Falcon uses specific ID fields. What raw data is used as the ' ParentProcessId_decimal ' when a process spawns a child process?
While reviewing the ' Detection Method ' field for a high-severity alert, a responder sees the label ' Post-Exploit ' . This terminology is used by CrowdStrike to identify a specific:
Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:
root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.
Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
