CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part2 Q21-40

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 21.

An analyst notices that a suspicious process created several child processes during a detection. What should the analyst examine to understand the execution chain?

  1. Process relationships
    2. Sensor update policy
    3. Host group membership
    4. User role permissions

Correct Answer: 1. Process relationships

Explanation:

Process relationships help responders understand how suspicious activity developed on an endpoint. By examining parent and child processes, the analyst can determine which executable initiated another process and identify subsequent actions in the execution chain. This is especially useful when investigating malware, script interpreters, command shells, or legitimate applications being abused. Host groups and sensor policies provide administrative context but do not reveal the execution sequence. User permissions may provide useful supporting information, but process relationships are the primary source for reconstructing how one process launched or interacted with another during suspicious endpoint activity.

Question 22.

A responder wants to identify all endpoints where a known malicious file hash has appeared. Which capability should be used first?

  1. User Search
    2. Host Timeline
    3. Hash Search
    4. IP Search

Correct Answer: 3. Hash Search

Explanation:

Hash Search is designed to investigate file hashes across the environment. When a known malicious hash is discovered, the responder can use this capability to identify whether the same file has appeared on additional endpoints. This helps determine the scope of an incident and whether the activity is isolated or widespread. Host Timeline focuses on chronological activity for a specific endpoint, while IP Search is intended for network indicators. User Search provides account-related context. Searching directly for the file hash is the most efficient first step when the investigation begins with a known malicious file identifier.

Question 23.

An analyst wants to determine what happened on a host immediately before a suspicious executable started. Which view would provide the most useful chronological context?

  1. Hash management
    2. Host Timeline
    3. User Search
    4. Sensor policy configuration

Correct Answer: 2. Host Timeline

Explanation:

Host Timeline provides chronological endpoint activity and is useful for understanding events that occurred before, during, and after suspicious behavior. By reviewing the timeline, an analyst can identify preceding processes, network events, file activity, or other relevant events that may explain how the suspicious executable was introduced or launched. Hash management is used to control file behavior rather than reconstruct endpoint activity. User Search focuses on identity-related information, and sensor policies configure endpoint protection settings. For an investigation that requires broad chronological context around a host, Host Timeline is the most appropriate starting point.

Question 24.

A responder needs to execute approved commands directly on a remote endpoint during incident containment. Which Falcon capability should be used?

  1. Bulk Domain Search
    2. Detection grouping
    3. Event Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response allows authorized responders to interact directly with supported endpoints during an investigation. Through an RTR session, responders can execute permitted commands, inspect files, collect information, and perform approved remediation actions. This capability is particularly useful when rapid endpoint-level investigation or containment is required. Bulk Domain Search is intended for domain indicators, while detection grouping helps organize detection information. Event Search provides historical telemetry but does not provide the same interactive endpoint access. RTR permissions should be carefully controlled because the commands executed during a session can directly affect endpoint systems and files.

Question 25.

An analyst observes a file that appears on thousands of endpoints across the organization. Which property is the analyst evaluating?

  1. External intelligence
    2. Internal prevalence
    3. Detection severity
    4. MITRE tactic

Correct Answer: 2. Internal prevalence

Explanation:

Internal prevalence describes how commonly a file, hash, or similar artifact appears within the organization’s environment. A highly prevalent file may be part of widely deployed legitimate software, although prevalence alone does not prove that a file is safe. Conversely, a rare file appearing on only one or two systems may deserve additional investigation, especially when accompanied by suspicious behavior. Detection severity reflects the importance assigned to a detection, while MITRE tactics describe adversary objectives. External intelligence concerns information gathered outside the organization. Internal prevalence therefore provides useful context when assessing whether observed files are common or unusual internally.

Question 26.

An analyst has identified a suspicious domain and wants to determine whether other systems communicated with it. Which search capability is most appropriate?

  1. Domain-related search
    2. User Search
    3. Hash Search
    4. RTR audit review

Correct Answer: 1. Domain-related search

Explanation:

A domain-related search allows the analyst to investigate whether endpoints in the environment have communicated with or referenced a particular domain. This is useful when threat intelligence identifies a suspicious command-and-control, phishing, or malware distribution domain. The results can help determine incident scope and reveal additional affected systems. User Search focuses on user accounts, while Hash Search is designed for file identifiers. RTR audit records document response actions rather than network communications. Matching the investigation tool to the indicator type helps responders work more efficiently and reduces unnecessary pivots during incident analysis.

Question 27.

During detection triage, an analyst wants to focus only on critical detections that remain unresolved. What should the analyst use?

  1. RTR scripts
    2. Detection filters
    3. Hash allowlisting
    4. Sensor uninstall tokens

Correct Answer: 2. Detection filters

Explanation:

Detection filters allow analysts to narrow large detection sets according to useful criteria such as severity, status, host, or other available properties. Applying filters makes triage more efficient because the responder can focus on the most relevant detections instead of reviewing everything at once. RTR scripts perform endpoint actions and do not organize detections. Hash allowlisting changes how particular files are handled and should not be used simply to reduce the detection list. Sensor uninstall controls are administrative functions unrelated to detection triage. Filtering is therefore the appropriate approach when prioritizing unresolved critical detections.

Question 28.

A responder needs to investigate a specific user account that may have been involved in suspicious endpoint activity. Which search should be used?

  1. Hash Search
    2. IP Search
    3. User Search
    4. Process Tree

Correct Answer: 3. User Search

Explanation:

User Search is designed to provide information associated with a particular user account. It can help responders investigate identity-related activity and determine where the account has been observed during an incident. This information can then be correlated with endpoint events, process activity, or other evidence. Hash Search focuses on files, while IP Search investigates network addresses. Process Tree shows execution relationships between processes rather than providing an account-centered investigation. When the investigation begins with a username or suspected account, User Search provides the most direct and relevant starting point.

Question 29.

An analyst wants to visualize how a suspicious command shell was launched and what processes it subsequently created. Which view is most useful?

  1. Process Tree
    2. Host group list
    3. Sensor policy page
    4. User role page

Correct Answer: 1. Process Tree

Explanation:

Process Tree visually represents process ancestry and descendants, allowing analysts to understand how a process was launched and which processes it later created. This makes it particularly useful when investigating suspicious command shells, scripts, malware loaders, or other activity involving multiple stages of execution. Administrative pages such as host groups, sensor policies, and user roles can provide configuration information but do not show process execution relationships. By reviewing the Process Tree, responders can reconstruct an execution chain and identify potentially malicious parent-child relationships that may require deeper investigation.

Question 30.

A responder has confirmed that a hash belongs to trusted business software that should be permitted. Which hash action is most appropriate?

  1. Block
    2. Detect Only
    3. Block and Hide Detection
    4. Allow

Correct Answer: 4. Allow

Explanation:

The Allow action is appropriate when a responder has verified that a file is trusted and should be permitted according to the organization’s security requirements. Before allowing a hash, the analyst should carefully confirm the file’s legitimacy because an incorrect allow decision could reduce protection against malicious activity. Block is intended for confirmed unwanted or malicious files, while Detect Only preserves monitoring without applying the same blocking action. Block and Hide Detection combines prevention with altered detection visibility. Hash actions should always be selected according to evidence, organizational policy, and the desired security outcome.

Question 31.

A security administrator wants to confirm which responder executed a particular RTR command during an incident. What should be reviewed?

  1. RTR audit information
    2. Process prevalence
    3. MITRE technique mapping
    4. Domain search results

Correct Answer: 1. RTR audit information

Explanation:

RTR audit information records activity associated with Real Time Response sessions and supports accountability during investigations. Reviewing these records can help determine which authorized responder initiated an action and what activity occurred during the session. This is important for incident documentation, governance, troubleshooting, and security oversight. Process prevalence describes how commonly an artifact occurs, while MITRE mappings describe adversary behavior. Domain search results provide network indicator information. None of those sources are intended to document administrative actions performed through RTR, making RTR audit information the appropriate source.

Question 32.

An analyst wants to investigate events associated specifically with one suspicious process rather than all activity on the endpoint. Which capability is most appropriate?

  1. Host Search
    2. Process Timeline
    3. Bulk Domain Search
    4. User Search

Correct Answer: 2. Process Timeline

Explanation:

Process Timeline focuses the investigation on events associated with a specific process. It provides context that helps responders understand what the process did and what relevant activity occurred around it. This is useful when the analyst has already identified a suspicious executable and wants a more targeted view than a full host timeline. Host Search provides broader endpoint information, while Bulk Domain Search focuses on domains. User Search focuses on identity activity. A process-centered timeline allows the responder to investigate the behavior of the selected process without being distracted by unrelated endpoint events.

Question 33.

An analyst wants to investigate communication involving a suspicious IP address found in a detection. Which tool should be selected?

  1. User Search
    2. Host Search
    3. IP Search
    4. Hash Search

Correct Answer: 3. IP Search

Explanation:

IP Search is intended for investigations centered on an IP address. It can help responders identify related activity and determine whether endpoints have communicated with a suspicious network destination. This is useful when an IP address is associated with command-and-control infrastructure, suspicious remote services, or other potentially malicious activity. User Search focuses on accounts, Host Search focuses on endpoints, and Hash Search focuses on file identifiers. Selecting IP Search allows the responder to begin with the network indicator and then pivot to affected systems or related events as the investigation develops.

Question 34.

A responder is considering a sensor visibility exclusion to reduce unwanted telemetry. What is the primary security concern?

  1. It may reduce investigation visibility
    2. It automatically blocks all files
    3. It increases detection severity
    4. It disables user authentication

Correct Answer: 1. It may reduce investigation visibility

Explanation:

A sensor visibility exclusion can reduce the telemetry available to security analysts for the excluded activity. While exclusions may be necessary in certain operational situations, they should be narrowly scoped and carefully evaluated because reduced visibility can create investigative blind spots. An analyst may later need the excluded telemetry to reconstruct an incident or detect suspicious behavior. Sensor visibility exclusions do not automatically block all files, increase detection severity, or disable authentication. Before applying an exclusion, responders should understand its exact effect and verify that the operational benefit outweighs the potential reduction in detection and investigation visibility.

Question 35.

A responder wants to examine information about a particular endpoint and identify relevant host-related context. Which search is the best starting point?

  1. User Search
    2. Host Search
    3. Hash Search
    4. Domain Search

Correct Answer: 2. Host Search

Explanation:

Host Search is the most appropriate starting point when an investigation is centered on a particular endpoint. It provides host-related information that can help analysts understand the system and determine suitable investigative pivots. From there, the responder may investigate processes, timelines, users, network activity, or other indicators associated with the device. User Search centers on identity activity, Hash Search examines files, and Domain Search focuses on domain indicators. Starting with Host Search keeps the investigation aligned with the endpoint and provides useful context before deeper analysis is performed.

Question 36.

A detection has been verified as a false positive caused by legitimate software. What should the analyst do before creating an exclusion?

  1. Create the broadest possible exclusion
    2. Disable endpoint protection
    3. Confirm the exclusion type and scope
    4. Delete all detection records

Correct Answer: 3. Confirm the exclusion type and scope

Explanation:

Before creating an exclusion, the analyst should determine exactly which exclusion mechanism is appropriate and limit its scope as much as possible. Different exclusions can affect detection, prevention, or visibility in different ways. A broad exclusion may unintentionally hide malicious behavior that resembles legitimate activity. Disabling endpoint protection creates unnecessary risk, while deleting detection records does not resolve the underlying issue. Careful validation of the software, exclusion type, path or behavior being excluded, and expected impact helps maintain strong security coverage while reducing unwanted false-positive activity.

Question 37.

An analyst wants to understand the adversary objective represented by activity mapped to Credential Access. What does Credential Access represent in MITRE ATT&CK?

  1. A tactic
    2. A vulnerability score
    3. A sensor policy
    4. A file reputation category

Correct Answer: 1. A tactic

Explanation:

Credential Access is a MITRE ATT&CK tactic representing an adversary objective involving the theft or acquisition of account credentials. Tactics describe the goals attackers attempt to achieve during different stages of malicious activity. Techniques beneath a tactic describe methods adversaries may use to accomplish that objective. Understanding this distinction helps responders interpret detection context and understand why certain behaviors are significant. Vulnerability scores belong to systems such as CVSS, while sensor policies configure endpoint protection. File reputation categories describe artifacts rather than adversary objectives. Credential Access is therefore classified as a MITRE ATT&CK tactic.

Question 38.

A responder wants to reuse a sequence of approved RTR commands across multiple incidents. What is the most efficient approach?

  1. Re-enter each command manually every time
    2. Create an RTR custom script
    3. Create a domain exclusion
    4. Change detection severity

Correct Answer: 2. Create an RTR custom script

Explanation:

An RTR custom script allows a repeatable series of response actions to be packaged for authorized use. This improves consistency and can reduce mistakes when the same remediation procedure is needed across multiple incidents. Scripts should be tested, appropriately permissioned, and audited because they may perform powerful endpoint actions. Re-entering commands manually increases operational effort and creates a greater opportunity for typing errors. Domain exclusions and detection severity changes do not execute remediation procedures. A custom RTR script is therefore the most efficient method for standardizing approved recurring response actions.

Question 39.

An analyst receives a list of suspicious domains from threat intelligence and wants to check all of them efficiently. Which capability should be selected?

  1. Host Timeline
    2. Process Tree
    3. Bulk Domain Search
    4. User Search

Correct Answer: 3. Bulk Domain Search

Explanation:

Bulk Domain Search is appropriate when responders need to investigate multiple domain indicators together. Threat intelligence feeds often provide several suspicious domains associated with phishing, malware delivery, or command-and-control infrastructure. Searching them in bulk can help the analyst quickly identify whether any have appeared within the environment and determine which endpoints require further investigation. Host Timeline examines endpoint activity over time, Process Tree shows process relationships, and User Search focuses on accounts. Bulk Domain Search is therefore the most efficient choice when the investigation begins with a collection of domain indicators.

Question 40.

An analyst is investigating suspicious activity and needs to broaden the investigation from a detection into detailed enterprise event data. Which capability is most appropriate?

  1. Hash Allow
    2. Sensor uninstall
    3. Host containment only
    4. Event Advanced Search

Correct Answer: 4. Event Advanced Search

Explanation:

Event Advanced Search allows responders to investigate detailed event telemetry and expand an investigation beyond the information initially presented in a detection. Analysts can search for related events, refine results, and pivot through available data to identify additional suspicious activity. This capability is valuable for understanding incident scope and reconstructing actions across endpoints. Hash Allow changes file handling, while sensor uninstall is an administrative action. Host containment may be appropriate during response but does not provide the detailed event analysis needed for investigation. Event Advanced Search is therefore the appropriate choice for deeper enterprise telemetry analysis.