CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 181.

An analyst discovers a suspicious command shell and wants to determine which application launched it. Which process relationship should be reviewed first?

  1. Parent process
    2. Child process
    3. Host group
    4. Sensor policy

Correct Answer: 1. Parent process

Explanation:

The parent process identifies the process that directly launched another process. Reviewing it helps the analyst determine how suspicious execution started and can reveal unusual relationships, such as a document application launching a command interpreter. Child processes show activity created afterward, while host groups and sensor policies provide administrative context rather than execution details. Examining the parent process is therefore the most direct way to identify the origin of a suspicious command shell and begin reconstructing the process chain involved in the detection.

Question 182.

A responder has identified a malicious SHA-256 hash and wants to locate other endpoints where the same file was observed. Which capability should be used?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Host Timeline

Correct Answer: 2. Hash Search

Explanation:

Hash Search is designed for investigations that begin with a known file hash. It helps responders determine whether the same file has appeared on additional endpoints and can reveal whether suspicious activity is isolated or widespread. User Search focuses on accounts, IP Search focuses on network addresses, and Host Timeline provides chronological endpoint activity. When the known indicator is a SHA-256 value, Hash Search provides the most direct method for locating related files and identifying systems that may require further investigation.

Question 183.

An analyst wants to reconstruct all relevant activity across an endpoint in chronological order. Which capability is most appropriate?

  1. Process Tree
    2. User Search
    3. Host Timeline
    4. Hash management

Correct Answer: 3. Host Timeline

Explanation:

Host Timeline provides a chronological view of activity across an endpoint. It helps responders understand what occurred before, during, and after suspicious behavior and can reveal related events that were not obvious from the original detection. Process Tree focuses on hierarchical process relationships, while User Search and hash management address different investigation or control requirements. When the analyst needs a broad, time-based view of endpoint behavior, Host Timeline is the most appropriate capability for reconstructing the sequence of events.

Question 184.

A responder must remotely inspect an endpoint and execute approved remediation commands. Which Falcon capability should be used?

  1. Detection filters
    2. Bulk Domain Search
    3. Hash Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response allows authorized responders to interact directly with supported endpoints. Through RTR, they can execute approved commands, inspect files, collect information, and perform remediation without physically accessing the device. Detection filters organize alerts, while Bulk Domain Search and Hash Search investigate indicators without providing direct endpoint control. Because RTR can perform significant actions, organizations should carefully manage permissions and review audit records. RTR is therefore the appropriate capability when active remote investigation or remediation is required.

Question 185.

A file appears on only one endpoint in an environment containing thousands of systems. Which characteristic is being evaluated?

  1. Internal prevalence
    2. Detection status
    3. User permission
    4. Sensor policy

Correct Answer: 1. Internal prevalence

Explanation:

Internal prevalence measures how commonly an artifact appears within the organization’s environment. A file seen on only one endpoint has very low internal prevalence and may warrant closer investigation, particularly when other suspicious indicators exist. Low prevalence does not automatically mean that a file is malicious, so analysts should combine it with behavioral, reputation, process, and network evidence. Detection status, user permissions, and sensor policies provide different types of information and do not describe how widespread a file is across enterprise systems.

Question 186.

A confirmed malicious file must be prevented from executing. Which hash-management action should the responder choose?

  1. Allow
    2. Block
    3. Detect Only
    4. No action

Correct Answer: 2. Block

Explanation:

Block is appropriate when a file represented by a hash has been confirmed as malicious and should be prevented from executing. Detect Only preserves visibility without providing the same prevention behavior, while Allow is intended for trusted software. No action would not meet the requirement to stop execution. Responders should validate a hash carefully before blocking it because an incorrect decision could disrupt legitimate applications. The selected hash-management action should always align with the intended prevention and visibility outcome.

Question 187.

An investigation begins with a specific user account suspected of participating in malicious activity. Which capability should be used first?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Process Timeline

Correct Answer: 1. User Search

Explanation:

User Search is the most appropriate starting point when the investigation centers on a username or account. It can provide identity-related information and help responders identify endpoints or activity associated with the user. The analyst can then pivot into process activity, detections, network indicators, or timelines as needed. Hash Search focuses on files, IP Search focuses on network addresses, and Process Timeline focuses on a particular process. User Search therefore provides the most direct investigation path when the known indicator is an account.

Question 188.

A suspicious IP address appears in multiple detections. Which capability should be used to investigate related network activity?

  1. Process Tree
    2. Hash Search
    3. IP Search
    4. User Search

Correct Answer: 3. IP Search

Explanation:

IP Search is intended for investigations involving network addresses. It can help responders identify endpoint activity associated with a suspicious IP and determine whether multiple systems communicated with it. This is useful when investigating potential command-and-control infrastructure or suspicious remote services. Process Tree focuses on process execution, Hash Search focuses on file indicators, and User Search focuses on identities. When the primary indicator is an IP address, IP Search provides the most relevant starting point for further analysis.

Question 189.

An analyst wants to narrow thousands of detections to only high-severity unresolved items. What should be used?

  1. Detection filters
    2. RTR scripts
    3. Hash Allow
    4. Sensor exclusions

Correct Answer: 1. Detection filters

Explanation:

Detection filters allow analysts to narrow detection queues by attributes such as severity, status, host, and other available criteria. Filtering for unresolved high-severity detections helps responders prioritize the most important activity without changing endpoint protection settings. RTR scripts execute response actions, while hash actions and sensor exclusions alter security behavior or visibility. Those options are not designed simply to organize alert lists. Detection filtering is therefore the correct approach when the goal is to focus on a specific subset of detections during triage.

Question 190.

An analyst wants a chronological view focused exclusively on one suspicious process. Which capability should be selected?

  1. Host Timeline
    2. Process Timeline
    3. User Search
    4. Bulk Domain Search

Correct Answer: 2. Process Timeline

Explanation:

Process Timeline provides a chronological view centered on a particular process. It allows the analyst to investigate events associated with the suspicious executable without reviewing unrelated activity across the entire endpoint. Host Timeline provides broader host-wide context, while User Search and Bulk Domain Search focus on other indicator types. When the analyst already knows which process requires investigation and wants a targeted behavioral view, Process Timeline is the most appropriate capability for understanding activity surrounding that process.

Question 191.

A manager needs to verify which responder executed a command during a Real Time Response session. Which records should be reviewed?

  1. RTR audit logs
    2. Process Tree
    3. Detection severity
    4. Internal prevalence

Correct Answer: 1. RTR audit logs

Explanation:

RTR audit logs provide records of actions performed during Real Time Response sessions. They help organizations identify which authorized responder executed commands and support accountability, compliance, troubleshooting, and incident documentation. Process Tree shows endpoint process relationships, while detection severity helps prioritize alerts and internal prevalence measures how common an artifact is. None of those sources provide the administrative audit trail needed to identify RTR actions. Reviewing RTR audit logs is therefore the appropriate way to verify responder activity.

Question 192.

A threat intelligence report provides dozens of suspicious domains. Which capability offers the most efficient way to investigate them?

  1. Bulk Domain Search
    2. User Search
    3. Host Timeline
    4. Process Tree

Correct Answer: 1. Bulk Domain Search

Explanation:

Bulk Domain Search is designed for investigating multiple domain indicators efficiently. It allows responders to check a large list of suspicious domains without manually performing separate searches for each one. This can be useful when threat intelligence identifies phishing, malware-delivery, or command-and-control infrastructure. User Search focuses on identities, Host Timeline provides endpoint chronology, and Process Tree focuses on process relationships. For a large collection of domain indicators, Bulk Domain Search provides the most efficient and focused investigative approach.

Question 193.

A suspicious executable starts PowerShell and several system utilities. Which process relationship should the analyst review to understand what happened after execution?

  1. Parent process
    2. Child processes
    3. Host group
    4. Sensor version

Correct Answer: 2. Child processes

Explanation:

Child processes are processes launched by another process. Reviewing them helps analysts understand the downstream activity that followed execution of a suspicious executable. In this scenario, PowerShell and system utilities could represent discovery, persistence, credential access, or other malicious behavior depending on how they were used. Parent process analysis identifies what launched the suspicious executable, while host groups and sensor versions provide administrative context. Child-process analysis is therefore essential for understanding what actions occurred after the original process started.

Question 194.

A responder verifies that a file is trusted enterprise software and should be permitted to execute. Which hash action should be selected?

  1. Block
    2. Detect Only
    3. Allow
    4. Block and Hide Detection

Correct Answer: 3. Allow

Explanation:

Allow is appropriate when a file has been verified as trusted and should execute normally according to organizational policy. The responder should carefully confirm the hash and file identity before applying the action because incorrectly allowing malicious software could reduce protection. Block prevents execution, while Detect Only maintains monitoring without the same blocking behavior. Block and Hide Detection is intended for a different security outcome. For confirmed legitimate software that should run normally, Allow is the appropriate hash-management choice.

Question 195.

An analyst wants to expand a detection investigation into detailed enterprise event telemetry. Which capability should be used?

  1. Event Advanced Search
    2. User role configuration
    3. Sensor update settings
    4. Host group creation

Correct Answer: 1. Event Advanced Search

Explanation:

Event Advanced Search allows responders to investigate detailed telemetry beyond the information initially shown in a detection. Analysts can search related events, refine results, and pivot through additional evidence to determine the scope and sequence of suspicious activity. User roles, sensor update settings, and host groups are administrative functions and do not provide deep telemetry analysis. When a detection requires further investigation using enterprise event data, Event Advanced Search is the appropriate capability for identifying additional evidence and understanding broader activity.

Question 196.

A legitimate application repeatedly triggers detections. What is the best approach before creating an exclusion?

  1. Exclude the entire host
    2. Disable prevention globally
    3. Verify the behavior and use the narrowest appropriate exclusion
    4. Ignore every future alert from the application

Correct Answer: 3. Verify the behavior and use the narrowest appropriate exclusion

Explanation:

Before creating an exclusion, the responder should confirm that the activity is genuinely legitimate and understand the effect of the exclusion type being considered. The scope should be kept as narrow as possible to avoid creating unnecessary blind spots. Excluding an entire host or disabling prevention globally would significantly reduce security coverage. Ignoring all future alerts could also hide unrelated malicious behavior. Careful validation and narrow scoping allow the organization to reduce false positives while preserving as much detection, prevention, and investigation visibility as possible.

Question 197.

Within MITRE ATT&CK, what does a technique represent?

  1. A high-level adversary objective
    2. A method used by an adversary to achieve an objective
    3. A detection severity level
    4. A host configuration policy

Correct Answer: 2. A method used by an adversary to achieve an objective

Explanation:

A technique in MITRE ATT&CK describes a method adversaries use to achieve a broader objective. Tactics represent those high-level objectives, such as Execution, Persistence, Credential Access, Discovery, or Exfiltration. Techniques describe how attackers may pursue those goals. Understanding this distinction helps responders interpret ATT&CK mappings and connect suspicious behavior to an attack sequence. Detection severity and host configuration policies are separate security concepts and do not represent adversary methods within the ATT&CK framework.

Question 198.

A team performs the same series of RTR commands during many incidents. What should be created to make the process reusable and consistent?

  1. An RTR custom script
    2. A sensor visibility exclusion
    3. A detection filter
    4. A domain allowlist

Correct Answer: 1. An RTR custom script

Explanation:

An RTR custom script allows a repeatable series of approved commands to be packaged into a reusable response workflow. This improves consistency and reduces the likelihood of errors caused by entering commands manually during every incident. Scripts should be tested carefully and restricted to authorized responders because they can perform significant endpoint actions. Sensor exclusions affect visibility, detection filters organize alerts, and domain allowlists serve different purposes. An RTR custom script is therefore the most appropriate option for standardizing repeated remediation procedures.

Question 199.

An analyst suspects that suspicious activity found on one endpoint may be part of a broader incident. Which investigation approach is most appropriate?

  1. Review only the original detection
    2. Correlate hosts, users, processes, hashes, domains, and IP addresses
    3. Close the detection immediately
    4. Disable telemetry on other endpoints

Correct Answer: 2. Correlate hosts, users, processes, hashes, domains, and IP addresses

Explanation:

Determining incident scope requires correlating multiple types of evidence across the environment. The analyst should examine related hosts, users, processes, file hashes, domains, IP addresses, timelines, and event data. This can reveal whether suspicious activity appears on additional systems or involves other accounts. Reviewing only the original detection may miss connected activity, while immediately closing it could leave a compromise unresolved. Disabling telemetry would reduce visibility. Correlating multiple evidence types provides the strongest basis for understanding whether an incident is isolated or widespread.

Question 200.

A suspicious process launches several scripts, command-line utilities, and additional executables. What should the analyst review next?

  1. Subscription information
    2. Console theme settings
    3. Host naming conventions
    4. Child processes and related events

Correct Answer: 4. Child processes and related events

Explanation:

Child processes and related events reveal what occurred after the suspicious process started. Reviewing them can expose scripts, payloads, reconnaissance commands, credential-access attempts, persistence mechanisms, or other potentially malicious behavior. This information helps the analyst reconstruct the attack chain and determine what additional response actions may be required. Subscription details, interface settings, and host naming conventions do not explain endpoint behavior. Examining child processes and associated event activity is therefore the most appropriate next investigative step.