CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part6 Q101-120

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 101.

An analyst discovers that a suspicious process spawned a command shell and several system utilities. Which view would best help reconstruct this execution chain?

  1. Process Tree
    2. Host group settings
    3. User role settings
    4. Sensor update policy

Correct Answer: 1. Process Tree

Explanation:

Process Tree is designed to display hierarchical relationships between processes, including parents and children. It allows an analyst to determine what launched a suspicious process and what that process subsequently created. In this scenario, reviewing the command shell and system utilities within the tree can help reconstruct the sequence of execution and identify potentially malicious behavior. Host groups, user roles, and sensor update policies provide administrative information rather than execution context. Process Tree is therefore the most appropriate tool for understanding multi-stage process relationships during an endpoint investigation.

Question 102.

A responder identifies a suspicious SHA-256 hash and needs to determine whether the same file exists on other endpoints. What should be used?

  1. IP Search
    2. Hash Search
    3. User Search
    4. Domain Search

Correct Answer: 2. Hash Search

Explanation:

Hash Search is used when the investigation begins with a known file hash. It can help responders identify whether the same file has appeared elsewhere across the environment and determine which hosts may be affected. This is particularly useful when scoping malware or suspicious executable activity. IP Search focuses on network addresses, User Search focuses on account activity, and Domain Search focuses on domain indicators. Hash Search is therefore the most direct way to investigate the prevalence and distribution of a suspicious file based on its SHA-256 value.

Question 103.

An analyst needs a broad chronological view of activity occurring on one endpoint before and after a detection. Which capability should be selected?

  1. Host Timeline
    2. User Search
    3. Hash management
    4. Bulk Domain Search

Correct Answer: 1. Host Timeline

Explanation:

Host Timeline provides a chronological view of endpoint activity and is useful when an analyst wants to understand what occurred across a system over a period of time. It can reveal events that happened before and after the initial detection and help connect related activity. User Search focuses on identity information, Hash management controls file handling, and Bulk Domain Search is intended for multiple domain indicators. When the investigation requires a broad endpoint-level chronology rather than a single process view, Host Timeline is the most appropriate capability.

Question 104.

A responder must remotely inspect files and execute approved remediation commands on an affected endpoint. Which Falcon capability is most appropriate?

  1. Detection filtering
    2. User Search
    3. Bulk Domain Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response provides authorized responders with direct remote access to supported endpoints for investigation and remediation. Through an RTR session, an analyst can run permitted commands, inspect files, collect information, and perform approved response actions. Detection filters help organize alerts, while User Search and Bulk Domain Search provide investigation context without direct endpoint interaction. Because RTR commands can affect endpoint systems, organizations should control permissions carefully and maintain appropriate auditing. For remote investigation and remediation, Real Time Response is the correct capability.

Question 105.

A suspicious executable is found on only one workstation in an environment containing thousands of endpoints. Which characteristic is being evaluated?

  1. Internal prevalence
    2. Detection status
    3. Sensor version
    4. User role

Correct Answer: 1. Internal prevalence

Explanation:

Internal prevalence describes how common or rare an artifact is within the organization’s own environment. A file appearing on only one workstation has very low internal prevalence and may deserve additional investigation, particularly if its behavior is also suspicious. However, rarity alone does not prove maliciousness. Analysts should combine prevalence with process behavior, reputation, network activity, and other evidence. Detection status, sensor version, and user role provide different information and do not directly measure how widely a file appears across managed endpoints.

Question 106.

A file hash has been confirmed as malicious and must be prevented from executing while normal detection visibility remains available. Which action should be selected?

  1. Allow
    2. Block
    3. Detect Only
    4. No action

Correct Answer: 2. Block

Explanation:

Block is the appropriate action when the organization has confirmed that a file represented by a hash is malicious and wants to prevent its execution. This option provides prevention while maintaining detection visibility. Detect Only can preserve detection without applying the same prevention action, while Allow is intended for trusted content. No action does not meet the requirement to prevent execution. Responders should validate the hash carefully before blocking it because an incorrect decision could disrupt legitimate software. Hash-management actions should always reflect the intended security outcome.

Question 107.

An investigation begins with a username suspected of being involved in malicious activity. Which search capability is the best starting point?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Process Timeline

Correct Answer: 1. User Search

Explanation:

User Search is the most suitable starting point when an investigation centers on a specific account. It can provide information associated with that user and help responders identify related systems or activity. From there, the analyst can pivot into detections, endpoint events, processes, or other evidence. Hash Search focuses on files, IP Search focuses on network addresses, and Process Timeline focuses on activity associated with a process. When the known indicator is a username, User Search provides the most direct investigative path.

Question 108.

A detection contains a suspicious IP address believed to be associated with command-and-control activity. Which tool should the analyst use first?

  1. User Search
    2. Process Tree
    3. IP Search
    4. Hash Search

Correct Answer: 3. IP Search

Explanation:

IP Search is the most appropriate tool when the known indicator is a network address. It can help analysts determine whether endpoints in the environment have communicated with the suspicious IP and identify related activity. This is valuable when investigating potential command-and-control infrastructure or suspicious remote services. User Search focuses on accounts, Process Tree shows process execution relationships, and Hash Search focuses on files. Starting with IP Search allows the responder to gather network-specific context and identify systems that may require further investigation.

Question 109.

An analyst wants to display only unresolved high-severity detections from a large queue. Which feature should be used?

  1. Detection filters
    2. RTR custom scripts
    3. Hash blocking
    4. Sensor exclusions

Correct Answer: 1. Detection filters

Explanation:

Detection filters allow analysts to narrow a large queue according to criteria such as severity, status, host, or other available properties. This helps responders focus on the most important alerts without changing endpoint security settings. RTR scripts perform endpoint actions, Hash blocking changes file enforcement, and Sensor exclusions can reduce telemetry or detection coverage. None of those features are intended simply to organize or prioritize the detection queue. Filtering is therefore the correct approach when the analyst needs to focus on unresolved high-severity detections.

Question 110.

An analyst wants to investigate events associated specifically with a suspicious process rather than reviewing all activity on the endpoint. Which capability is most appropriate?

  1. Host Timeline
    2. Process Timeline
    3. User Search
    4. Bulk Domain Search

Correct Answer: 2. Process Timeline

Explanation:

Process Timeline provides a focused chronological view of activity associated with a particular process. It is useful when the analyst has already identified a suspicious executable and wants to understand its behavior without reviewing every unrelated event on the endpoint. Host Timeline provides broader host-wide context, while User Search and Bulk Domain Search investigate different types of indicators. When the investigation is centered on one process, Process Timeline is the most appropriate tool for examining related events and understanding the process’s behavior.

Question 111.

A manager asks which responder executed a particular command during an RTR session. Where should the analyst look?

  1. Process Tree
    2. RTR audit logs
    3. Detection severity
    4. Internal prevalence

Correct Answer: 2. RTR audit logs

Explanation:

RTR audit logs provide records of actions performed during Real Time Response sessions. They support accountability by allowing security teams to review who initiated actions and what occurred during remote response activity. Process Tree displays endpoint execution relationships, while detection severity helps prioritize alerts and internal prevalence shows how common an artifact is. None of those sources identify the responder responsible for RTR commands. Audit information is therefore the appropriate place to verify command execution and user activity during RTR sessions.

Question 112.

A threat intelligence report contains dozens of suspicious domains. Which capability allows the responder to investigate them most efficiently?

  1. Bulk Domain Search
    2. Host Timeline
    3. User Search
    4. Process Tree

Correct Answer: 1. Bulk Domain Search

Explanation:

Bulk Domain Search is designed to efficiently investigate multiple domain indicators. It allows responders to evaluate a list of suspicious domains without manually searching each one through separate workflows. This is particularly useful when threat intelligence identifies phishing, malware-delivery, or command-and-control domains. Host Timeline focuses on activity from one endpoint, User Search focuses on account activity, and Process Tree focuses on process relationships. When the investigation begins with many domains, Bulk Domain Search provides the most efficient method for identifying possible matches in the environment.

Question 113.

A suspicious process was launched by an unexpected application. Which process relationship helps identify the application that started it?

  1. Parent process
    2. Child process
    3. Sibling process
    4. Host group

Correct Answer: 1. Parent process

Explanation:

The parent process identifies the process responsible for launching another process. Reviewing it can help analysts determine how suspicious execution began and reveal abnormal relationships, such as an office application spawning a command shell. Child processes show activity launched afterward, while sibling processes share a common parent but do not directly identify what launched the suspicious executable. Host groups are administrative constructs rather than execution relationships. Examining the parent process is therefore the most direct method for identifying the application that initiated the suspicious process.

Question 114.

An analyst has verified that a file belongs to trusted software and should be permitted to execute. Which hash-management action is most appropriate?

  1. Block
    2. Detect Only
    3. Allow
    4. Block and Hide Detection

Correct Answer: 3. Allow

Explanation:

Allow is appropriate when a file has been positively verified as trusted and should be permitted according to organizational policy. The responder should confirm the hash carefully before selecting this action because incorrectly allowing malicious software could reduce protection. Block prevents execution, while Detect Only continues monitoring without applying the same prevention behavior. Block and Hide Detection is intended for a different security outcome. For confirmed legitimate software that should execute normally, Allow is the hash-management option that best matches the requirement.

Question 115.

An analyst wants to expand a detection investigation into detailed enterprise telemetry and search for related events. Which capability should be used?

  1. Event Advanced Search
    2. Host group creation
    3. Sensor uninstall
    4. Hash Allow

Correct Answer: 1. Event Advanced Search

Explanation:

Event Advanced Search allows responders to examine detailed event telemetry beyond the initial detection. It can be used to search for related activity, refine results, and identify additional evidence connected to suspicious behavior. This helps analysts determine incident scope and reconstruct the sequence of events. Host group creation and sensor uninstall are administrative actions, while Hash Allow changes how a file is treated. None of those functions provide the detailed event investigation capability offered by Event Advanced Search.

Question 116.

A legitimate application repeatedly causes unwanted detections. What should the responder do before creating an exclusion?

  1. Exclude the entire endpoint
    2. Validate the behavior and choose the narrowest suitable exclusion
    3. Disable all prevention policies
    4. Ignore every future detection from the application

Correct Answer: 2. Validate the behavior and choose the narrowest suitable exclusion

Explanation:

Before creating an exclusion, the responder should verify that the activity is genuinely legitimate and understand the effect of the proposed exclusion type. The scope should be as narrow as possible so that unrelated malicious activity remains visible and protected. Excluding an entire endpoint or disabling prevention would unnecessarily weaken security. Ignoring all future detections is also unsafe because behavior may change. Careful validation and limited scoping help reduce false positives while preserving as much protection and investigative visibility as possible.

Question 117.

Within MITRE ATT&CK, which element represents the method an adversary uses to achieve an objective?

  1. Tactic
    2. Technique
    3. Severity
    4. Policy

Correct Answer: 2. Technique

Explanation:

In MITRE ATT&CK, techniques describe methods adversaries use to accomplish their objectives. Tactics represent the higher-level objectives, such as Persistence, Credential Access, Discovery, or Exfiltration. A technique explains how an attacker may pursue one of those goals. Understanding the relationship between tactics and techniques helps responders interpret ATT&CK mappings and place suspicious endpoint behavior into a broader attack context. Severity and policy are separate security concepts and are not ATT&CK elements describing adversary methods.

Question 118.

A security team wants to reuse the same sequence of approved RTR commands during recurring incidents. What is the most appropriate solution?

  1. Create an RTR custom script
    2. Create a broad sensor exclusion
    3. Change detection severity
    4. Create a user group

Correct Answer: 1. Create an RTR custom script

Explanation:

An RTR custom script allows a security team to package a repeatable sequence of response commands into a reusable workflow. This can improve consistency, reduce manual typing, and lower the chance of errors during recurring remediation tasks. Scripts should be tested and restricted to authorized responders because they may perform significant actions on endpoints. Sensor exclusions affect visibility, while changing detection severity or creating user groups does not perform remediation. A custom RTR script is therefore the most appropriate solution for standardized recurring response procedures.

Question 119.

An analyst must determine whether suspicious activity seen on one endpoint is part of a wider incident. Which approach provides the strongest investigation?

  1. Review only the original detection
    2. Correlate hosts, users, hashes, processes, and network indicators
    3. Immediately close the detection
    4. Disable telemetry collection

Correct Answer: 2. Correlate hosts, users, hashes, processes, and network indicators

Explanation:

Determining incident scope requires correlating multiple sources of evidence. The analyst should examine related hosts, user accounts, process relationships, file hashes, network indicators, timelines, and relevant event data. This helps identify whether the same behavior or indicators appear elsewhere in the environment. Reviewing only the initial detection may miss related compromise, while closing the detection prematurely could leave malicious activity unresolved. Disabling telemetry would reduce visibility. Correlating several evidence types provides the strongest basis for determining whether an incident is isolated or widespread.

Question 120.

A suspicious executable launches several command-line utilities and scripts. What should the analyst investigate next to understand downstream behavior?

  1. Child processes and related event activity
    2. Console display settings
    3. Subscription configuration
    4. Host naming convention

Correct Answer: 1. Child processes and related event activity

Explanation:

Child processes and related events reveal what happened after the suspicious executable started. Reviewing them may expose reconnaissance commands, credential access attempts, persistence mechanisms, lateral movement activity, or other malicious behavior. This information helps the analyst reconstruct the execution chain and determine the scope and severity of the incident. Console settings, subscription configuration, and host naming conventions do not explain endpoint behavior. Investigating downstream child processes and associated events is therefore the most appropriate next step in the analysis.