Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

CCFR-201b CrowdStrike Certified Falcon Responder is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

CCFR-201b Practice Questions

CrowdStrike Certified Falcon Responder

Last Update 4 days ago
Total Questions : 209

Dive into our fully updated and stable CCFR-201b practice test platform, featuring all the latest CCFR exam questions added this week. Our preparation tool is more than just a CrowdStrike study aid; it's a strategic advantage.

Our free CCFR practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about CCFR-201b. Use this test to pinpoint which areas you need to focus your study on.

CCFR-201b PDF

CCFR-201b PDF (Printable)
$54.25
$154.99

CCFR-201b Testing Engine

CCFR-201b PDF (Printable)
$59.5
$169.99

CCFR-201b PDF + Testing Engine

CCFR-201b PDF (Printable)
$74.55
$212.99
Question # 41

CrowdScore is a metric used to identify the severity of an ongoing incident. What percentage of increase in a CrowdScore is considered a strong indication of a coordinated attack?

Options:

A.  

10%

B.  

20%

C.  

50%

D.  

100%

Discussion 0
Question # 42

An analyst wants to see the raw events behind a specific detection. Which icon in the UI allows them to pivot directly to an event search?

Options:

A.  

Shield icon

B.  

Spyglass icon

C.  

Trash can icon

D.  

Gear icon

Discussion 0
Question # 43

You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?

Options:

A.  

User logons after the detection

B.  

Executions of schtasks.exe after the detection

C.  

Scheduled tasks registered prior to the detection

D.  

Pivot to a Hash search for taskeng.exe

Discussion 0
Question # 44

When using ' User Search ' to investigate a potentially compromised account, which of the following is NOT a filter available in the User Search?

Options:

A.  

Username

B.  

Hostname

C.  

Process ID

D.  

Time Range

Discussion 0
Question # 45

To track the relationship between a parent and its child, Falcon uses specific ID fields. What raw data is used as the ' ParentProcessId_decimal ' when a process spawns a child process?

Options:

A.  

The Operating System PID of the parent.

B.  

The TargetProcessId_decimal of the parent process.

C.  

The ContextProcessId_decimal of the system.

D.  

The RootProcessId_decimal of the entire tree.

Discussion 0
Question # 46

While reviewing the ' Detection Method ' field for a high-severity alert, a responder sees the label ' Post-Exploit ' . This terminology is used by CrowdStrike to identify a specific:

Options:

A.  

Falcon Detection Method

B.  

MITRE Tactic

C.  

Indicator of Attack (IOA)

D.  

Prevention Policy Level

Discussion 0
Question # 47

How long are quarantined files stored in the CrowdStrike Cloud?

Options:

A.  

45 Days

B.  

90 Days

C.  

Days

D.  

Quarantined files are not deleted

Discussion 0
Question # 48

The function of Machine Learning Exclusions is to___________.

Options:

A.  

stop all detections for a specific pattern ID

B.  

stop all sensor data collection for the matching path(s)

C.  

Stop all Machine Learning Preventions but a detection will still be generated and files will still be uploaded to the CrowdStrike Cloud

D.  

stop all ML-based detections and preventions for the matching path(s) and/or stop files from being uploaded to the CrowdStrike Cloud

Discussion 0
Question # 49

Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:

root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.

Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?

Options:

A.  

Remote exploitation of a system service

B.  

User execution via a Phishing email or drive-by download

C.  

Malicious persistence via a WMI event subscription

D.  

Credential theft through a compromised Domain Controller

Discussion 0
Question # 50

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Options:

A.  

Identifies a detailed list of all process executions for the specified hashes

B.  

Identifies hosts that loaded or executed the specified hashes

C.  

Identifies users associated with the specified hashes

D.  

Identifies detections related to the specified hashes

Discussion 0
Get CCFR-201b dumps and pass your exam in 24 hours!

Free Exams Sample Questions