CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 281.

An analyst sees a suspicious command interpreter launched by a browser process. Which evidence should be reviewed first to understand how the command interpreter started?

  1. Parent process
    2. Child processes
    3. Sensor version
    4. Host group

Correct Answer: 1. Parent process

Explanation:

The parent process identifies the process that directly launched another process. Reviewing it helps analysts understand the origin of suspicious execution and can reveal unusual relationships, such as a browser launching a command interpreter. Child processes show what happened afterward, while sensor versions and host groups provide administrative rather than execution context. Investigating the parent process is therefore the most direct way to determine how the suspicious process started and to begin reconstructing the activity that led to the detection.

Question 282.

A responder identifies a suspicious SHA-256 hash and wants to determine whether the same file appeared on other endpoints. Which capability should be used?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Host Timeline

Correct Answer: 2. Hash Search

Explanation:

Hash Search is designed to investigate a known file hash across the environment. It can help responders identify additional systems where the same file appeared and determine whether suspicious activity is isolated or widespread. User Search focuses on identities, IP Search focuses on network addresses, and Host Timeline provides chronological activity for a single endpoint. When the known indicator is a SHA-256 value, Hash Search offers the most direct way to locate related file activity and expand the scope of the investigation.

Question 283.

An analyst wants to reconstruct endpoint activity in chronological order during a suspected compromise. Which capability is most appropriate?

  1. Process Tree
    2. User Search
    3. Host Timeline
    4. Hash management

Correct Answer: 3. Host Timeline

Explanation:

Host Timeline provides a chronological view of endpoint activity and helps analysts reconstruct events surrounding suspicious behavior. It can reveal what occurred before, during, and after a detection and help connect related activity that may otherwise be overlooked. Process Tree focuses on process relationships rather than full host chronology. User Search focuses on identities, while hash management controls file actions. When the investigation requires broad time-based context across an endpoint, Host Timeline is the most appropriate investigative capability.

Question 284.

An authorized responder needs to remotely inspect files and perform approved remediation actions on an endpoint. Which capability should be selected?

  1. Detection filtering
    2. Bulk Domain Search
    3. User Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response allows authorized responders to interact directly with supported endpoints. Through RTR, they can execute approved commands, inspect files, collect evidence, and perform remediation remotely. Detection filtering organizes alerts, while Bulk Domain Search and User Search provide investigative information without direct endpoint control. Because RTR can make significant changes to systems, permissions should be tightly controlled and actions should be auditable. RTR is therefore the correct capability when active remote investigation or remediation is required.

Question 285.

A suspicious executable appears on only one endpoint in a very large environment. Which concept best describes this observation?

  1. Internal prevalence
    2. Detection severity
    3. Host containment
    4. User privilege

Correct Answer: 1. Internal prevalence

Explanation:

Internal prevalence describes how common or rare an artifact is within the organization’s own environment. A file observed on only one endpoint has low internal prevalence and may warrant additional investigation when combined with suspicious behavior. Low prevalence alone does not prove maliciousness, so analysts should also consider process activity, reputation, network connections, and other evidence. Detection severity, containment status, and user privileges describe different properties and do not indicate how widely a file appears across the organization.

Question 286.

A malicious file hash has been confirmed and the organization wants to prevent execution. Which hash-management action should be applied?

  1. Allow
    2. Block
    3. Detect Only
    4. No action

Correct Answer: 2. Block

Explanation:

Block is appropriate when a file hash has been confirmed as malicious and the organization wants to prevent the associated file from executing. Detect Only preserves visibility without providing the same prevention behavior, while Allow is intended for trusted files. No action does not satisfy the prevention requirement. Responders should carefully validate the hash before blocking it to avoid disrupting legitimate software. The chosen hash-management action should reflect the organization’s confidence in the evidence and the intended security outcome.

Question 287.

An analyst is investigating suspicious activity tied to a specific username. Which capability should be used first?

  1. User Search
    2. Hash Search
    3. Process Timeline
    4. IP Search

Correct Answer: 1. User Search

Explanation:

User Search is the best starting point when an investigation centers on a particular account. It can help identify activity and systems associated with the user and provide context for further pivots into detections, processes, hosts, or network indicators. Hash Search focuses on files, Process Timeline focuses on one process, and IP Search investigates network addresses. When the known starting indicator is a username, User Search provides the most direct identity-focused investigative path.

Question 288.

A detection contains an unfamiliar external IP address. Which capability should the analyst use to investigate whether other endpoints communicated with it?

  1. Hash Search
    2. User Search
    3. IP Search
    4. Process Tree

Correct Answer: 3. IP Search

Explanation:

IP Search is designed for investigations involving network addresses. It can help determine whether endpoints in the environment communicated with the suspicious IP and identify related activity. This is useful when examining potential command-and-control infrastructure or suspicious remote services. Hash Search focuses on file indicators, User Search focuses on identities, and Process Tree focuses on execution relationships. When the indicator is an IP address, IP Search provides the most relevant network-focused context.

Question 289.

An analyst wants to focus a large detection queue on unresolved high-severity detections. Which functionality should be used?

  1. Detection filters
    2. RTR custom scripts
    3. Sensor exclusions
    4. Hash Allow

Correct Answer: 1. Detection filters

Explanation:

Detection filters allow responders to narrow a large queue using criteria such as severity, status, host, or other available attributes. Filtering for unresolved high-severity detections helps analysts prioritize important activity without changing endpoint protection controls. RTR scripts execute response actions, sensor exclusions can reduce visibility, and hash actions modify file handling. None of those features is intended simply to organize detections. Filtering is therefore the appropriate method for focusing on a specific subset of alerts during triage.

Question 290.

An analyst wants a chronological view focused only on one suspicious process. Which capability should be used?

  1. Host Timeline
    2. Process Timeline
    3. User Search
    4. Bulk Domain Search

Correct Answer: 2. Process Timeline

Explanation:

Process Timeline provides a chronological view centered on a specific process and its associated activity. It is useful when the analyst already knows which process requires deeper investigation and wants to avoid unrelated host events. Host Timeline provides broader endpoint context, while User Search and Bulk Domain Search focus on different indicator types. Process Timeline therefore provides the most targeted view for understanding the behavior of one suspicious executable and its surrounding events.

Question 291.

A security manager needs to verify which responder executed commands during a Real Time Response session. What should be reviewed?

  1. RTR audit logs
    2. Internal prevalence
    3. Process Tree
    4. Detection severity

Correct Answer: 1. RTR audit logs

Explanation:

RTR audit logs provide records of actions performed during Real Time Response sessions. They allow organizations to identify which authorized responder executed particular commands and support accountability, incident documentation, troubleshooting, and compliance. Internal prevalence measures how common an artifact is, Process Tree shows execution relationships, and detection severity helps prioritize alerts. None of those sources provides the same audit trail. RTR audit logs are therefore the correct source for reviewing responder actions.

Question 292.

A threat intelligence feed provides dozens of suspicious domains. Which capability is most efficient for investigating them together?

  1. Bulk Domain Search
    2. Host Timeline
    3. User Search
    4. Process Tree

Correct Answer: 1. Bulk Domain Search

Explanation:

Bulk Domain Search is intended for investigations involving multiple domain indicators. It allows responders to evaluate many suspicious domains more efficiently than searching each one separately. This is useful when threat intelligence provides domains related to phishing, malware delivery, or command-and-control infrastructure. Host Timeline and Process Tree focus on endpoint behavior, while User Search focuses on identity activity. Bulk Domain Search is therefore the most efficient capability when the investigation begins with a large domain list.

Question 293.

A suspicious process launches several command-line utilities and scripts. Which relationship should the analyst examine to understand the downstream execution?

  1. Parent process
    2. Child processes
    3. Host group
    4. Sensor policy

Correct Answer: 2. Child processes

Explanation:

Child processes show which processes were launched by another process. Reviewing them helps analysts understand what actions occurred after the suspicious process started. Downstream processes may include command shells, discovery tools, scripts, credential-access utilities, or additional payloads. The parent process explains how the original process began but not what it launched afterward. Host groups and sensor policies provide administrative context. Child-process analysis is therefore essential for understanding subsequent execution behavior.

Question 294.

A responder verifies that a file is legitimate enterprise software and should be allowed to run. Which hash-management action is appropriate?

  1. Block
    2. Detect Only
    3. Allow
    4. Block and Hide Detection

Correct Answer: 3. Allow

Explanation:

Allow is appropriate when a file has been verified as trusted and should execute normally according to organizational policy. The responder should confirm the hash carefully before applying this action because mistakenly allowing malicious content could weaken security. Block prevents execution, while Detect Only provides monitoring without the same blocking behavior. Block and Hide Detection provides a different prevention and visibility outcome. For confirmed legitimate software, Allow is the appropriate hash-management action.

Question 295.

An analyst wants to investigate detailed event telemetry related to an existing detection. Which capability should be used?

  1. Event Advanced Search
    2. Host group configuration
    3. Sensor update policy
    4. User role management

Correct Answer: 1. Event Advanced Search

Explanation:

Event Advanced Search enables responders to investigate detailed telemetry beyond what is initially displayed in a detection. Analysts can search related events, refine results, and uncover additional evidence that may help determine the scope and sequence of suspicious activity. Host groups, sensor policies, and user roles are administrative capabilities rather than investigative search tools. When deeper event-level analysis is required, Event Advanced Search provides the appropriate functionality for expanding the investigation.

Question 296.

A legitimate application repeatedly triggers false-positive detections. What should guide the responder before creating an exclusion?

  1. Exclude the entire endpoint
    2. Disable prevention globally
    3. Confirm the behavior and use the narrowest suitable exclusion
    4. Ignore all future alerts from the application

Correct Answer: 3. Confirm the behavior and use the narrowest suitable exclusion

Explanation:

Before creating an exclusion, the responder should confirm that the activity is truly legitimate and understand how the exclusion type will affect detection, prevention, or visibility. The scope should be kept as narrow as possible to avoid unnecessary security blind spots. Excluding an entire endpoint or disabling prevention globally would significantly weaken protection. Ignoring future alerts could also hide unrelated malicious activity. A carefully validated and narrowly scoped exclusion provides a better balance between reducing false positives and preserving security coverage.

Question 297.

Within MITRE ATT&CK, which element represents the high-level objective an adversary is attempting to achieve?

  1. Tactic
    2. Technique
    3. Indicator
    4. Detection status

Correct Answer: 1. Tactic

Explanation:

A tactic in MITRE ATT&CK represents a high-level adversary objective, such as Execution, Persistence, Credential Access, Discovery, or Exfiltration. Techniques describe the methods attackers use to achieve those objectives. Understanding the difference helps responders interpret ATT&CK mappings and determine why suspicious activity may be occurring. Indicators and detection status are useful security concepts but do not represent adversary objectives within ATT&CK. Tactics provide the broader purpose behind attacker behavior.

Question 298.

A response team wants to reuse the same approved sequence of RTR commands across multiple incidents. What should be created?

  1. An RTR custom script
    2. A sensor exclusion
    3. A detection filter
    4. A host group

Correct Answer: 1. An RTR custom script

Explanation:

An RTR custom script allows an approved sequence of commands to be packaged into a reusable response procedure. This improves consistency, reduces manual typing errors, and can make recurring remediation tasks more efficient. Scripts should be tested carefully and limited to authorized responders because they may perform significant endpoint actions. Sensor exclusions affect visibility, detection filters organize alerts, and host groups organize endpoints. An RTR custom script is therefore the most appropriate solution for standardizing repeated response actions.

Question 299.

An analyst believes suspicious activity found on one endpoint may be part of a broader compromise. Which strategy is most appropriate?

  1. Review only the original alert
    2. Correlate hosts, users, processes, hashes, domains, and IP addresses
    3. Close the detection immediately
    4. Disable telemetry on unaffected endpoints

Correct Answer: 2. Correlate hosts, users, processes, hashes, domains, and IP addresses

Explanation:

Determining incident scope requires correlating multiple sources of evidence across the environment. Analysts should review related hosts, users, processes, hashes, domains, IP addresses, timelines, and event data. This can reveal additional affected systems or accounts and help determine whether suspicious behavior extends beyond the original endpoint. Reviewing only one alert can miss connected activity, while disabling telemetry would reduce visibility. Correlating several evidence types provides a stronger basis for understanding the complete scope of an incident.

Question 300.

A suspicious executable launches scripts, network tools, and additional processes. What should the analyst review next to understand what happened afterward?

  1. Subscription information
    2. Console appearance settings
    3. Host naming conventions
    4. Child processes and related events

Correct Answer: 4. Child processes and related events

Explanation:

Child processes and related events reveal what occurred after the suspicious executable started. Reviewing them may expose reconnaissance commands, credential-access activity, persistence attempts, additional payloads, or other malicious behavior. This information helps the analyst reconstruct the attack sequence and determine whether further investigation or remediation is required. Subscription details, console appearance settings, and host naming conventions do not explain endpoint execution behavior. Examining downstream process activity and related events is therefore the most appropriate next investigative step.