Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

CCFR-201b CrowdStrike Certified Falcon Responder is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

CCFR-201b Practice Questions

CrowdStrike Certified Falcon Responder

Last Update 4 days ago
Total Questions : 209

Dive into our fully updated and stable CCFR-201b practice test platform, featuring all the latest CCFR exam questions added this week. Our preparation tool is more than just a CrowdStrike study aid; it's a strategic advantage.

Our free CCFR practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about CCFR-201b. Use this test to pinpoint which areas you need to focus your study on.

CCFR-201b PDF

CCFR-201b PDF (Printable)
$54.25
$154.99

CCFR-201b Testing Engine

CCFR-201b PDF (Printable)
$59.5
$169.99

CCFR-201b PDF + Testing Engine

CCFR-201b PDF (Printable)
$74.55
$212.99
Question # 1

What happens when you create a Sensor Visibility Exclusion for a trusted file path?

Options:

A.  

It excludes host information from Detections and Incidents generated within that file path location

B.  

It prevents file uploads to the CrowdStrike cloud from that file path

C.  

It excludes sensor monitoring and event collection for the trusted file path

D.  

It disables detection generation from that path, however the sensor can still perform prevention actions

Discussion 0
Question # 2

Which statement is TRUE regarding the " Bulk Domains " search?

Options:

A.  

It will show a list of computers and process that performed a lookup of any of the domains in your search

B.  

The " Bulk Domains " search will allow you to blocklist your queried domains

C.  

The " Bulk Domains " search will show IP address and port information for any associated connections

D.  

You should only pivot to the " Bulk Domains " search tool after completing an investigation

Discussion 0
Question # 3

An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?

Options:

A.  

reg.exe

B.  

taskmgr.exe

C.  

lsass.exe

D.  

svchost.exe

Discussion 0
Question # 4

When a responder is looking at the ' Full Detection Details ' page, they can toggle between several views. Which of the following is NOT a layout option available for viewing these details?

Options:

A.  

Graph View

B.  

Tree View

C.  

Process Timeline

D.  

List View

Discussion 0
Question # 5

Responders must understand the limitations and capabilities of custom rules. Which of the following statements about custom IOAs is FALSE?

Options:

A.  

They can be used to monitor or block specific command-line strings.

B.  

A Custom IOA rule group can only be applied to one single prevention policy.

C.  

They can generate ' Informational ' detections if set to the ' Monitor ' action.

D.  

They allow for pattern matching using wildcards or specific strings.

Discussion 0
Question # 6

When reviewing the data within a process timeline, what specific type of information is being displayed to the responder?

Options:

A.  

A capture of all raw network packets sent by the process.

B.  

All cloudable process-related events (files written, network connections, etc.) for that process in a given timeframe.

C.  

A list of every user who has ever logged into that specific endpoint.

D.  

A summary of the hardware performance metrics during the time of the detection.

Discussion 0
Question # 7

Host Search is a powerful investigation tool. From which of the following sources is a responder most likely to pivot directly to a Host Search?

Options:

A.  

A global intelligence report about a new adversary.

B.  

A specific detection that occurred on a particular host.

C.  

The main settings menu of the Falcon console.

D.  

The help documentation in the Support portal.

Discussion 0
Question # 8

Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?

Options:

A.  

An adversary is trying to keep access through persistence by creating an account

B.  

An adversary is trying to keep access through persistence using browser extensions

C.  

An adversary is trying to keep access through persistence using external remote services

D.  

adversary is trying to keep access through persistence using application skimming

Discussion 0
Question # 9

What does pivoting to an Event Search from a detection do?

Options:

A.  

It gives you the ability to search for similar events on other endpoints quickly

B.  

It takes you to the raw Insight event data and provides you with a number of Event Actions

C.  

It takes you to a Process Timeline for that detection so you can see all related events

D.  

It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection

Discussion 0
Question # 10

A responder is focused on a specific malicious script and wants to see everything that the script ' s process did. Which timeline is the best tool for this task?

Options:

A.  

Host Timeline

B.  

Process Timeline

C.  

User Timeline

D.  

Administrative Timeline

Discussion 0
Get CCFR-201b dumps and pass your exam in 24 hours!

Free Exams Sample Questions