View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps
Question 201.
An analyst is reviewing a detection where a browser unexpectedly launched a command-line interpreter. Which information would provide the clearest execution context?
- Parent-child process relationships
2. Host naming convention
3. Sensor installation date
4. User interface settings
Correct Answer: 1. Parent-child process relationships
Explanation:
Parent-child process relationships help analysts understand how processes were launched and how execution progressed. In this scenario, the browser is the parent process and the command-line interpreter is its child. Such an unusual relationship may warrant deeper investigation because browsers do not normally launch command shells during routine activity. Reviewing related processes and events can reveal whether additional commands, scripts, or payloads were executed. Host naming conventions, sensor installation dates, and interface settings provide administrative information but do not explain the suspicious execution sequence.
Question 202.
A responder has a suspicious file hash and wants to determine how common the file is across the organization. Which capability should be used?
- User Search
2. Hash Search
3. Process Timeline
4. IP Search
Correct Answer: 2. Hash Search
Explanation:
Hash Search is appropriate when the investigation begins with a known file hash. It can help the responder determine where the file has appeared and whether it is common or rare across organizational endpoints. This information can support incident scoping and provide additional context about the artifact. User Search focuses on identities, Process Timeline examines activity associated with a specific process, and IP Search investigates network addresses. When the known indicator is a file hash, Hash Search offers the most direct method for identifying related systems and file activity.
Question 203.
An analyst needs to determine what occurred across an endpoint during the hour surrounding a suspicious detection. Which view is most appropriate?
- Hash management
2. User Search
3. Host Timeline
4. Detection grouping
Correct Answer: 3. Host Timeline
Explanation:
Host Timeline provides a chronological view of activity across an endpoint, making it useful for reconstructing what occurred before and after suspicious behavior. The analyst can review surrounding events and identify activity that may be connected to the original detection. Hash management controls file actions, while User Search focuses on identity-related information. Detection grouping helps organize detections but does not provide the same chronological endpoint context. Host Timeline is therefore the most appropriate view when an investigation requires a broad sequence of events across a system.
Question 204.
An authorized responder needs to remotely investigate an endpoint and execute remediation commands. Which capability should be used?
- Bulk Domain Search
2. Detection sorting
3. Real Time Response
4. User Search
Correct Answer: 3. Real Time Response
Explanation:
Real Time Response enables authorized responders to interact directly with an endpoint during an investigation. It can be used to execute permitted commands, inspect files, gather information, and perform approved remediation actions remotely. Bulk Domain Search investigates domain indicators, detection sorting organizes alerts, and User Search focuses on identities. None of those capabilities provides direct endpoint interaction. Because RTR actions can affect systems and data, organizations should restrict access appropriately and maintain an audit trail of response activity.
Question 205.
An analyst observes that an executable is found on thousands of systems throughout the organization. Which investigative factor does this describe?
- Internal prevalence
2. Detection source
3. User privilege
4. Host containment status
Correct Answer: 1. Internal prevalence
Explanation:
Internal prevalence describes how frequently an artifact appears within the organization’s environment. An executable found on thousands of systems has high internal prevalence. This information can provide useful context, but prevalence alone does not determine whether a file is legitimate or malicious. Analysts should also evaluate process behavior, reputation, related detections, and other evidence. Detection source, user privilege, and containment status provide different forms of context and do not measure how widely an artifact appears across enterprise systems.
Question 206.
A responder wants Falcon to detect activity involving a particular hash without applying the same execution prevention associated with blocking. Which action is most appropriate?
- Allow
2. Detect Only
3. Block
4. Block and Hide Detection
Correct Answer: 2. Detect Only
Explanation:
Detect Only is appropriate when the responder wants continued visibility into activity involving a particular hash without applying the same blocking behavior as a Block action. This can be useful when an organization wants to monitor an artifact while gathering more evidence. Allow is intended for trusted files, while Block prevents the associated file from executing under applicable controls. Block and Hide Detection has a different prevention and visibility outcome. The chosen hash action should reflect both the organization’s security objective and the confidence of the investigation.
Question 207.
A responder is investigating possible malicious activity associated with a compromised account. Which capability should be used as the primary identity-focused search?
- User Search
2. Hash Search
3. Process Tree
4. IP Search
Correct Answer: 1. User Search
Explanation:
User Search provides an identity-focused starting point for investigations involving a particular account. It can help responders identify activity associated with the user and establish connections to relevant systems or events. From there, the analyst may pivot into detections, processes, hosts, or network indicators. Hash Search focuses on file artifacts, Process Tree visualizes process relationships, and IP Search investigates network addresses. When the known indicator is an account, User Search offers the most appropriate initial investigative perspective.
Question 208.
An analyst discovers a suspicious remote IP address and wants to identify endpoint activity associated with it. Which search should be performed?
- Hash Search
2. User Search
3. IP Search
4. Process Timeline
Correct Answer: 3. IP Search
Explanation:
IP Search is designed for investigations centered on network addresses. It can help analysts identify endpoints or events associated with the suspicious IP and determine whether the address appears elsewhere in environmental activity. This is useful when investigating potential command-and-control infrastructure or suspicious remote connections. Hash Search focuses on files, User Search focuses on accounts, and Process Timeline focuses on a particular process. When the indicator is an IP address, IP Search provides the most direct path to relevant network context.
Question 209.
An analyst needs to quickly prioritize detections by severity and then review only those still requiring investigation. Which functionality is most useful?
- Filtering and sorting
2. RTR scripting
3. Hash allowlisting
4. Sensor exclusion creation
Correct Answer: 1. Filtering and sorting
Explanation:
Filtering and sorting allow responders to organize large detection queues according to useful properties such as severity, status, or other available attributes. This makes it easier to prioritize higher-risk detections and focus on items that remain unresolved. RTR scripting performs endpoint actions, while hash allowlisting and sensor exclusions modify security behavior or visibility. Those features are not intended simply to organize detections. Filtering and sorting provide an efficient way to manage triage without changing endpoint protection controls.
Question 210.
An analyst has identified one suspicious process and wants to examine only the events most closely associated with that process. Which capability should be selected?
- Host Timeline
2. Process Timeline
3. User Search
4. Bulk Domain Search
Correct Answer: 2. Process Timeline
Explanation:
Process Timeline provides a focused view of events associated with a particular process. This makes it useful when the analyst has already identified the process of interest and wants to understand its behavior without reviewing unrelated endpoint activity. Host Timeline provides a broader host-wide view, while User Search and Bulk Domain Search focus on different indicator types. A process-centered timeline can help reveal what the suspicious process did and how its activity fits into the surrounding execution sequence.
Question 211.
A responder wants to verify the actions taken during a previous Real Time Response session. Which information should be reviewed?
- RTR audit logs
2. Internal prevalence
3. Process ancestry
4. Detection severity
Correct Answer: 1. RTR audit logs
Explanation:
RTR audit logs provide a record of activity performed through Real Time Response. They can help responders and administrators review which actions occurred during a session and support accountability, incident documentation, and troubleshooting. Internal prevalence measures how common an artifact is, while process ancestry describes execution relationships. Detection severity helps prioritize alerts. None of those sources provides the same record of RTR activity. Reviewing audit information is therefore the appropriate way to verify actions taken during remote response sessions.
Question 212.
A threat intelligence report contains a large collection of domains that may be related to malicious infrastructure. Which capability should the analyst use?
- Process Tree
2. Bulk Domain Search
3. User Search
4. Host Timeline
Correct Answer: 2. Bulk Domain Search
Explanation:
Bulk Domain Search is useful when an analyst needs to investigate many domain indicators efficiently. Instead of checking each domain individually, the responder can work with a collection of indicators and identify relevant activity more effectively. This is helpful for lists associated with phishing, malware delivery, or command-and-control infrastructure. Process Tree focuses on execution relationships, User Search focuses on identities, and Host Timeline focuses on chronological endpoint activity. Bulk Domain Search is therefore the most appropriate option for a large domain dataset.
Question 213.
A suspicious process launches a credential-related utility and several command-line tools. Which evidence should be examined to understand the downstream activity?
- Child processes
2. Parent process only
3. Host group settings
4. Sensor update settings
Correct Answer: 1. Child processes
Explanation:
Child processes reveal which processes were launched by the suspicious process. Reviewing them helps the analyst determine what happened after the original executable started and may expose additional tools, scripts, or commands used during an attack. The parent process explains what launched the suspicious process but does not provide the full downstream execution chain. Host group and sensor update settings are administrative information. Child-process analysis is therefore the most useful approach for understanding actions initiated by the suspicious process.
Question 214.
An analyst has confirmed that a file is approved and trustworthy. Which hash-management action best matches the requirement to permit the file?
- Block
2. Detect Only
3. Allow
4. Block and Hide Detection
Correct Answer: 3. Allow
Explanation:
Allow is appropriate when a responder has confirmed that a file is trusted and should be permitted according to organizational policy. Before applying the action, the file and hash should be carefully validated to reduce the risk of allowing malicious content. Block prevents execution, while Detect Only maintains detection without the same blocking effect. Block and Hide Detection produces a different prevention and visibility outcome. For verified software that should execute normally, Allow is the hash-management action that best meets the requirement.
Question 215.
A detection provides limited context, and the analyst wants to investigate related telemetry throughout the environment. Which capability is most appropriate?
- Event Advanced Search
2. Host grouping
3. Sensor configuration
4. User role management
Correct Answer: 1. Event Advanced Search
Explanation:
Event Advanced Search allows the analyst to move beyond the information contained in an individual detection and investigate detailed event telemetry. The responder can search for related events, refine results, and identify additional evidence that may help determine the sequence or scope of suspicious activity. Host grouping, sensor configuration, and user role management are administrative functions and do not provide comparable event investigation capabilities. Event Advanced Search is therefore the appropriate choice when deeper telemetry analysis is required.
Question 216.
A security team plans to create an exclusion for verified legitimate activity. Which principle should guide the exclusion configuration?
- Use the broadest possible scope
2. Disable prevention before testing
3. Use the narrowest scope that resolves the issue
4. Exclude all activity from the affected host
Correct Answer: 3. Use the narrowest scope that resolves the issue
Explanation:
Exclusions can reduce detection, prevention, or visibility, so they should be configured as narrowly as possible. The responder should first verify that the behavior is legitimate and then select the exclusion type and scope that address the issue without unnecessarily suppressing unrelated activity. Broad exclusions can create blind spots that attackers may exploit. Disabling protection or excluding all host activity would unnecessarily weaken security. A narrowly scoped exclusion provides a better balance between reducing false positives and preserving endpoint visibility.
Question 217.
Which MITRE ATT&CK concept describes the objective behind adversary behavior, such as Persistence or Discovery?
- Tactic
2. Technique
3. Indicator
4. Detection status
Correct Answer: 1. Tactic
Explanation:
A tactic represents a high-level adversary objective within MITRE ATT&CK. Examples include Persistence, Discovery, Credential Access, Execution, and Exfiltration. Techniques describe the specific methods adversaries use to accomplish those objectives. Understanding this distinction helps analysts interpret ATT&CK mappings and understand why observed activity may be occurring. Indicators and detection status are useful security concepts but do not represent adversary objectives within the ATT&CK framework. Tactics therefore provide the higher-level context for attacker behavior.
Question 218.
A response team wants to turn a frequently used group of RTR commands into a repeatable procedure. What should be created?
- An RTR custom script
2. A sensor exclusion
3. A detection filter
4. A host naming rule
Correct Answer: 1. An RTR custom script
Explanation:
An RTR custom script allows responders to package a recurring sequence of approved commands into a reusable procedure. This can improve response consistency and reduce manual entry errors during repeated remediation tasks. Custom scripts should be carefully tested and limited to authorized users because they can perform powerful actions on endpoints. Sensor exclusions reduce visibility, detection filters organize detections, and host naming rules do not execute remediation actions. A custom RTR script is therefore the most appropriate solution for repeatable response procedures.
Question 219.
An analyst identifies suspicious activity on one host and wants to determine whether the same incident affects other systems. Which strategy is most appropriate?
- Correlate related indicators and activity across the environment
2. Review only the first detection
3. Close the incident after containing one host
4. Disable logging on unaffected endpoints
Correct Answer: 1. Correlate related indicators and activity across the environment
Explanation:
Incident scoping requires looking beyond the initial endpoint. The analyst should correlate relevant hashes, processes, users, domains, IP addresses, hosts, and event activity across the environment. This can reveal additional affected systems or accounts and help determine whether the suspicious behavior is isolated or part of a larger compromise. Reviewing only one detection may miss related evidence, while closing the investigation too early can leave malicious activity unresolved. Maintaining telemetry and correlating evidence provides a stronger basis for understanding the incident’s scope.
Question 220.
An analyst sees an unusual process launching scripts, network utilities, and additional executables. What is the best next investigative action?
- Review the downstream processes and associated events
2. Change the host’s display name
3. Modify the console appearance
4. Review subscription information
Correct Answer: 1. Review the downstream processes and associated events
Explanation:
Reviewing downstream processes and associated events helps the analyst understand what actions followed execution of the suspicious process. The scripts, utilities, and executables may represent discovery, persistence, credential access, lateral movement, or other malicious behavior. Examining these relationships helps reconstruct the attack sequence and identify additional evidence that may require response. Host display names, console appearance, and subscription information do not explain endpoint activity. Downstream process and event analysis is therefore the most relevant next investigative step.