CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 61.

An analyst finds an unusual PowerShell process spawned by a Microsoft Office application. Which investigative view would best help determine the complete execution chain?

  1. Process Tree
    2. Host group configuration
    3. Sensor update policy
    4. User role settings

Correct Answer: 1. Process Tree

Explanation:

Process Tree provides a hierarchical view of parent and child processes and is ideal for reconstructing suspicious execution chains. In this scenario, the analyst can identify which Office process launched PowerShell and determine whether PowerShell subsequently started additional suspicious processes. This relationship is important because unusual parent-child combinations can indicate malicious document execution or script-based activity. Host groups, sensor policies, and user role settings provide administrative information rather than behavioral evidence. Process Tree therefore gives the analyst the clearest view of how the suspicious PowerShell activity originated and what actions followed.

Question 62.

A responder identifies a suspicious domain in several detections and wants to determine whether the domain appears elsewhere across the environment. Which capability is most appropriate?

  1. Host Search
    2. Domain Search
    3. Hash Search
    4. User Search

Correct Answer: 2. Domain Search

Explanation:

Domain Search is appropriate when the responder needs to investigate activity related to a particular domain. It can help identify whether endpoints have communicated with or referenced the domain elsewhere in the environment. This is useful when investigating potential command-and-control infrastructure, phishing domains, or malware distribution sites. Host Search focuses on endpoint information, Hash Search examines file identifiers, and User Search focuses on identity activity. Matching the search capability to the indicator type helps responders work efficiently and identify potentially related systems or events that require further investigation.

Question 63.

An analyst wants to determine what activity occurred immediately after a suspicious process started. Which capability provides the most focused view?

  1. Process Timeline
    2. Sensor visibility exclusion
    3. Host group membership
    4. User role assignment

Correct Answer: 1. Process Timeline

Explanation:

Process Timeline provides a chronological view centered on a particular process and its associated activity. It is useful when the analyst already knows which process is suspicious and wants to determine what happened before or after its execution. The responder can examine relevant events without reviewing all unrelated endpoint activity. Sensor visibility exclusions affect telemetry collection, while host groups and user roles are administrative features. Process Timeline is therefore the most focused investigative tool for understanding events associated with a specific suspicious process.

Question 64.

A responder needs to remotely investigate a compromised endpoint and collect additional evidence without physically accessing the device. Which capability should be used?

  1. Hash Search
    2. Bulk Domain Search
    3. User Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response allows authorized security personnel to remotely interact with an endpoint during an investigation. Through RTR, responders can run approved commands, inspect files, collect evidence, and perform remediation actions without physically accessing the system. This is especially valuable when endpoints are distributed across multiple locations. Hash Search, Bulk Domain Search, and User Search provide investigative context but do not provide direct endpoint interaction. Because RTR can make significant changes to systems, organizations should control access carefully and review activity through appropriate auditing mechanisms.

Question 65.

An analyst sees that a suspicious file exists on only one endpoint in the entire organization. Which factor is being evaluated?

  1. Internal prevalence
    2. Detection severity
    3. Sensor version
    4. User privilege level

Correct Answer: 1. Internal prevalence

Explanation:

Internal prevalence measures how commonly an artifact such as a file appears within the organization’s environment. A file observed on only one endpoint has low internal prevalence and may deserve additional investigation, particularly when combined with suspicious behavior. However, rarity alone does not prove that a file is malicious. Analysts should evaluate prevalence alongside process behavior, threat intelligence, hashes, network activity, and other evidence. Detection severity and sensor version provide different types of context, while user privileges describe account permissions rather than how widespread a file is.

Question 66.

A responder has verified that a hash belongs to malicious software and wants to prevent execution while maintaining normal detection visibility. Which action should be selected?

  1. Detect Only
    2. Block
    3. Allow
    4. No action

Correct Answer: 2. Block

Explanation:

Block is appropriate when a file hash has been confirmed as malicious and the organization wants to prevent the associated file from executing. This action provides prevention while retaining detection visibility. Detect Only would continue identifying the file without providing the same blocking behavior. Allow is intended for trusted content, and No action does not enforce prevention. Before applying a Block action, responders should confirm that the hash is accurate and corresponds to the intended malicious file because incorrect blocking decisions can affect legitimate applications and business operations.

Question 67.

An analyst wants to investigate endpoint activity related to a particular employee account. Which search should be used?

  1. User Search
    2. IP Search
    3. Hash Search
    4. Process Timeline

Correct Answer: 1. User Search

Explanation:

User Search is the most appropriate starting point when an investigation centers on a particular account. It can help responders identify activity associated with the user and provide context that can be correlated with endpoint events, detections, processes, or other evidence. IP Search focuses on network indicators, while Hash Search is designed for file identifiers. Process Timeline focuses on events associated with a specific process rather than an identity. Using User Search allows the responder to begin with the known account and pivot into related systems or suspicious activity.

Question 68.

A responder wants to determine whether a suspicious IP address communicated with multiple endpoints in the environment. Which tool should be used?

  1. Process Tree
    2. User Search
    3. IP Search
    4. Hash management

Correct Answer: 3. IP Search

Explanation:

IP Search is specifically designed for investigations centered on network addresses. It can help the responder identify endpoints or events associated with the suspicious IP address and determine whether communication occurred across multiple systems. This is useful when investigating potential command-and-control servers, suspicious external services, or other network-based indicators. Process Tree focuses on execution relationships, while User Search focuses on accounts. Hash management controls file behavior rather than network activity. IP Search is therefore the most appropriate tool for examining the scope of activity related to an IP address.

Question 69.

An analyst needs to focus a large detection queue on only unresolved high-severity detections. Which feature should be used?

  1. Detection filters
    2. RTR scripts
    3. Hash exclusions
    4. Sensor uninstall controls

Correct Answer: 1. Detection filters

Explanation:

Detection filters allow responders to narrow a large detection queue using properties such as severity, status, host, or other available attributes. This helps analysts prioritize the most important detections without changing endpoint security settings. RTR scripts are used for remote endpoint actions, while hash exclusions affect file handling. Sensor uninstall controls are administrative features unrelated to detection prioritization. By applying filters for unresolved and high-severity detections, the analyst can quickly focus on incidents that require immediate attention and improve the efficiency of the triage process.

Question 70.

A responder wants a chronological view of all relevant activity on one endpoint during a suspected compromise. Which capability is most appropriate?

  1. User Search
    2. Host Timeline
    3. Hash Search
    4. Bulk Domain Search

Correct Answer: 2. Host Timeline

Explanation:

Host Timeline provides a chronological view of endpoint events and is useful when reconstructing what occurred on a system during a suspected compromise. It helps analysts identify activity that happened before and after detections and understand how different events may be related. User Search focuses on account activity, Hash Search focuses on file indicators, and Bulk Domain Search investigates multiple domains. When the primary goal is to understand the sequence of activity across an entire endpoint, Host Timeline provides the broadest and most appropriate chronological context.

Question 71.

An analyst discovers that legitimate software repeatedly generates detections. Before creating an exclusion, what should the analyst do first?

  1. Disable endpoint protection
    2. Delete previous detections
    3. Validate the behavior and exclusion scope
    4. Exclude the entire system drive

Correct Answer: 3. Validate the behavior and exclusion scope

Explanation:

Before creating an exclusion, the analyst should verify that the detected activity is genuinely legitimate and determine the narrowest possible exclusion scope. Different exclusion types can affect visibility, prevention, or detection coverage, so an unnecessarily broad exclusion may create a security blind spot. Disabling endpoint protection or excluding an entire drive would significantly reduce protection and should not be used simply to address false positives. Careful validation ensures that the exclusion solves the operational issue without unnecessarily weakening security monitoring or allowing unrelated malicious behavior to bypass detection.

Question 72.

A responder wants to confirm who executed commands during an RTR session. Which information should be reviewed?

  1. MITRE ATT&CK mapping
    2. RTR audit logs
    3. Process prevalence
    4. Detection severity

Correct Answer: 2. RTR audit logs

Explanation:

RTR audit logs provide records of Real Time Response activity and are useful for determining which responder performed specific actions during a session. These records support accountability, incident documentation, troubleshooting, and compliance requirements. MITRE ATT&CK mappings describe adversary behavior, while prevalence shows how common an artifact is within an environment. Detection severity helps prioritize alerts but does not identify who performed RTR actions. Reviewing RTR audit logs is therefore the appropriate method for verifying command execution and responder activity during remote investigation or remediation sessions.

Question 73.

A security team needs to investigate 40 suspicious domains provided by threat intelligence. Which method is most efficient?

  1. Bulk Domain Search
    2. Start RTR on every endpoint
    3. Create a separate host group for each domain
    4. Search all user accounts individually

Correct Answer: 1. Bulk Domain Search

Explanation:

Bulk Domain Search is designed to investigate multiple domain indicators efficiently. Instead of checking each domain through separate manual workflows, responders can use bulk searching to determine whether the indicators have appeared within the environment. This is useful when threat intelligence provides lists of command-and-control, phishing, or malware-related domains. Starting RTR sessions across all endpoints would be unnecessarily intrusive, while creating host groups or searching user accounts would not directly address domain activity. Bulk Domain Search is therefore the most efficient method for handling a large domain indicator set.

Question 74.

An analyst wants to determine which process originally launched a suspicious executable. Which relationship should be examined?

  1. Child process
    2. Sibling process
    3. Parent process
    4. Host group

Correct Answer: 3. Parent process

Explanation:

The parent process identifies which process launched or created the suspicious executable. Examining this relationship is essential when reconstructing how suspicious activity began. For example, if a scripting engine was launched by an unusual document application, the parent-child relationship may reveal the initial attack vector. Child processes show what the suspicious process launched afterward, while sibling processes share a common parent but do not necessarily explain how the executable started. Host groups are administrative constructs and do not provide process execution relationships. Parent process analysis is therefore the correct approach.

Question 75.

A responder verifies that a file is trusted business software and should be permitted to execute. Which hash action is most appropriate?

  1. Detect Only
    2. Block
    3. Block and Hide Detection
    4. Allow

Correct Answer: 4. Allow

Explanation:

Allow is appropriate when the responder has verified that the file is legitimate and should be permitted according to organizational policy. Before applying an Allow action, the analyst should confirm the hash carefully to avoid unintentionally trusting malicious software. Block would prevent execution, while Detect Only would continue monitoring without applying the same prevention behavior. Block and Hide Detection is designed for a different use case involving blocking and altered detection visibility. For confirmed trusted software that should execute normally, Allow is the action that most directly meets the requirement.

Question 76.

An analyst wants to understand detailed enterprise telemetry associated with a detection and search for related events. Which capability should be used?

  1. Sensor uninstall
    2. Event Advanced Search
    3. Host group creation
    4. Hash Allow

Correct Answer: 2. Event Advanced Search

Explanation:

Event Advanced Search allows analysts to investigate detailed telemetry beyond the information initially presented in a detection. The responder can search for related events, refine results, and identify additional evidence connected to the suspicious activity. This can help determine incident scope and reconstruct actions across endpoints. Sensor uninstall and host group creation are administrative tasks, while Hash Allow changes how a particular file is treated. None of those options provide deep event analysis. Event Advanced Search is therefore the appropriate capability when the analyst needs to broaden a detection investigation using detailed enterprise telemetry.

Question 77.

In MITRE ATT&CK, what does a tactic represent?

  1. A malware hash
    2. An adversary objective
    3. A detection severity level
    4. A sensor configuration

Correct Answer: 2. An adversary objective

Explanation:

A MITRE ATT&CK tactic represents a high-level objective that an adversary is attempting to achieve during an attack. Examples include Initial Access, Credential Access, Discovery, Persistence, and Exfiltration. Techniques describe the specific methods used to achieve those objectives. Understanding tactics helps responders interpret the purpose behind suspicious behavior and place individual detections into a broader attack context. Tactics are not hashes, detection severity levels, or endpoint configurations. They are part of a behavioral framework that helps security teams analyze adversary actions consistently.

Question 78.

A security team repeatedly performs the same RTR remediation procedure across incidents. What should be created to improve consistency?

  1. A custom RTR script
    2. A broad sensor exclusion
    3. A new detection severity
    4. A domain allowlist

Correct Answer: 1. A custom RTR script

Explanation:

A custom RTR script can combine approved commands into a reusable remediation workflow. This helps responders perform repeated incident-response actions consistently and reduces the risk of manual command-entry errors. Custom scripts should be tested and limited to authorized users because they may perform powerful actions on endpoints. Broad exclusions can reduce visibility, while changing detection severity does not perform remediation. A domain allowlist addresses network indicators rather than endpoint response procedures. For a repeatable sequence of RTR commands, a custom script is the most efficient and consistent approach.

Question 79.

An analyst wants to determine whether suspicious activity is limited to one system or affects multiple endpoints. Which approach is most appropriate?

  1. Review only the original alert
    2. Correlate hashes, hosts, users, processes, and network indicators
    3. Immediately close the detection
    4. Disable endpoint telemetry

Correct Answer: 2. Correlate hashes, hosts, users, processes, and network indicators

Explanation:

Incident scoping requires correlating multiple sources of evidence. Analysts should examine hashes, affected hosts, user accounts, process relationships, network indicators, timelines, and related events to determine whether suspicious activity exists elsewhere. Reviewing only the original detection can miss related compromise, while closing the alert prematurely could leave the incident unresolved. Disabling endpoint telemetry would reduce visibility and make investigation more difficult. Correlating different evidence types provides a broader understanding of the incident and helps determine whether activity is isolated or part of a larger attack.

Question 80.

An analyst sees a suspicious executable launching multiple command-line tools. What is the best next step for understanding the downstream behavior?

  1. Review the child processes and related events
    2. Change the console theme
    3. Remove the host from all groups
    4. Delete the detection immediately

Correct Answer: 1. Review the child processes and related events

Explanation:

Reviewing child processes and related events helps the analyst understand what actions occurred after the suspicious executable started. Command-line tools may indicate discovery, credential access, persistence, lateral movement, or other malicious behavior depending on how they are used. Process relationships and surrounding events can reveal the complete sequence of activity and provide evidence needed for further response. Changing interface settings or host groups does not explain the behavior, while deleting the detection would remove useful investigative context. Examining downstream process activity is therefore the appropriate next step.