CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps

 

Question 141.

An analyst reviewing suspicious execution needs to determine what launched a command interpreter. Which process relationship should be examined first?

  1. Parent process
    2. Child process
    3. Sibling process
    4. Host group

Correct Answer: 1. Parent process

Explanation:

The parent process identifies the process that directly launched another process. Reviewing it helps the analyst understand how suspicious execution began and can expose unusual process relationships, such as a document application launching a command interpreter. Child processes show what the suspicious process started afterward, while sibling processes share a common parent but do not identify the direct launcher. Host groups are administrative constructs rather than execution relationships. Examining the parent process is therefore the most direct way to determine the origin of a suspicious process during an investigation.

Question 142.

A responder has a SHA-256 value for a suspicious executable and wants to identify other systems where it has appeared. Which capability should be used?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Host Timeline

Correct Answer: 2. Hash Search

Explanation:

Hash Search is designed for investigations that begin with a file hash. It can help responders determine whether the same executable has appeared on other endpoints and identify potentially affected systems. This is useful for determining whether malicious activity is isolated or widespread. User Search focuses on identities, IP Search investigates network addresses, and Host Timeline provides chronological activity for a host. When the known indicator is a SHA-256 hash, Hash Search is the most direct and efficient method for locating related file activity across the environment.

Question 143.

An analyst wants to examine a complete chronological sequence of events on an endpoint during a suspected intrusion. Which capability is most appropriate?

  1. Process Tree
    2. User Search
    3. Host Timeline
    4. Hash management

Correct Answer: 3. Host Timeline

Explanation:

Host Timeline provides chronological activity across an endpoint and is useful for reconstructing what occurred during a suspected intrusion. The analyst can review events that happened before and after suspicious behavior and identify related activity that may not be visible in the original detection. Process Tree focuses on process relationships rather than complete host chronology. User Search focuses on identity activity, and hash management controls file actions. When the investigation requires a broad time-based view across the entire endpoint, Host Timeline is the most suitable capability.

Question 144.

A responder needs to remotely collect information and execute approved commands on a compromised endpoint. Which Falcon capability should be selected?

  1. Bulk Domain Search
    2. Detection filters
    3. Hash Search
    4. Real Time Response

Correct Answer: 4. Real Time Response

Explanation:

Real Time Response provides authorized responders with remote interaction capabilities for supported endpoints. Through RTR, the analyst can execute approved commands, inspect files, collect information, and perform remediation actions without physically accessing the device. Bulk Domain Search investigates domain indicators, Detection filters organize alerts, and Hash Search focuses on files across the environment. Those capabilities do not provide direct endpoint control. Because RTR can affect endpoint systems, access should be limited to authorized responders and activity should be reviewed through appropriate audit records.

Question 145.

A file appears on nearly every workstation in the organization. Which characteristic is the analyst evaluating?

  1. Internal prevalence
    2. Detection severity
    3. ATT&CK tactic
    4. User role

Correct Answer: 1. Internal prevalence

Explanation:

Internal prevalence describes how commonly a file or artifact appears within the organization’s own environment. A file present on nearly every workstation has very high internal prevalence. This can provide useful investigative context, although high prevalence alone does not prove that a file is legitimate. Analysts should also evaluate reputation, behavior, process relationships, and other evidence. Detection severity and ATT&CK tactics describe different security concepts, while user roles control access. Internal prevalence is therefore the correct factor for measuring how widespread a file is across enterprise systems.

Question 146.

A malicious file hash has been confirmed and the organization wants to stop the associated file from executing. Which action is most appropriate?

  1. Detect Only
    2. Block
    3. Allow
    4. No action

Correct Answer: 2. Block

Explanation:

Block is the appropriate hash-management action when a file is confirmed as malicious and should be prevented from executing. Detect Only maintains detection visibility but does not provide the same blocking behavior. Allow is intended for trusted software, while No action does not meet the requirement to prevent execution. Before blocking a hash, the responder should verify that the value corresponds to the intended malicious file because an incorrect block could affect legitimate applications. Hash-management actions should always be selected according to the required prevention and visibility outcome.

Question 147.

An analyst is investigating suspicious activity tied to a particular employee account. Which search provides the best starting point?

  1. User Search
    2. Hash Search
    3. IP Search
    4. Process Tree

Correct Answer: 1. User Search

Explanation:

User Search is the most appropriate starting point when the investigation centers on a particular user account. It can provide identity-related information and help the analyst identify systems or activity associated with that account. The responder can then pivot into detections, endpoint events, process relationships, or network indicators as needed. Hash Search focuses on files, IP Search focuses on network addresses, and Process Tree focuses on execution relationships. Starting with User Search keeps the investigation aligned with the known identity indicator.

Question 148.

A suspicious external IP address is associated with several alerts. Which search capability should the responder use to investigate it?

  1. Hash Search
    2. Process Timeline
    3. IP Search
    4. User Search

Correct Answer: 3. IP Search

Explanation:

IP Search is designed for investigations centered on network addresses. It can help the responder identify related activity, determine whether multiple endpoints communicated with the suspicious IP, and assess the possible scope of network-based activity. Hash Search focuses on files, Process Timeline focuses on a particular process, and User Search focuses on identity activity. When the known indicator is an external IP address, IP Search provides the most direct route to additional network context and related endpoint evidence.

Question 149.

An analyst wants to display only open critical detections from a specific group of endpoints. What should be used?

  1. Detection filters
    2. RTR scripts
    3. Sensor exclusions
    4. Hash allowlisting

Correct Answer: 1. Detection filters

Explanation:

Detection filters allow responders to narrow detection queues using criteria such as status, severity, host, or host group. This helps analysts quickly focus on the alerts most relevant to the investigation without altering endpoint protection settings. RTR scripts perform response actions, sensor exclusions can reduce security visibility, and hash allowlisting changes how trusted files are handled. None of these features are intended simply to organize a detection queue. Filtering is therefore the correct approach when the analyst needs to focus on open critical detections from selected endpoints.

Question 150.

An analyst wants to focus on events related to one suspicious process rather than all events occurring on the host. Which capability should be used?

  1. Host Timeline
    2. Process Timeline
    3. User Search
    4. Bulk Domain Search

Correct Answer: 2. Process Timeline

Explanation:

Process Timeline provides a focused chronological view of events associated with a specific process. It is particularly useful when the analyst has already identified the suspicious executable and wants to understand its behavior without reviewing unrelated host activity. Host Timeline provides broader endpoint context, while User Search and Bulk Domain Search investigate identities and domains. By using Process Timeline, the responder can concentrate on events that are directly relevant to the process and better understand its actions within the attack chain.

Question 151.

A security administrator needs to confirm which user executed commands through Real Time Response during an incident. What should be reviewed?

  1. RTR audit logs
    2. Process Tree
    3. Internal prevalence
    4. Detection grouping

Correct Answer: 1. RTR audit logs

Explanation:

RTR audit logs provide records of actions performed during Real Time Response sessions. They allow security teams to review which authorized user performed specific commands and help support incident documentation, accountability, troubleshooting, and compliance. Process Tree displays endpoint execution relationships, internal prevalence measures how common an artifact is, and detection grouping organizes alerts. None of those sources provide an administrative audit trail for RTR activity. RTR audit logs are therefore the correct place to verify responder actions during an incident.

Question 152.

A responder receives a list of many suspicious domains and wants to check them efficiently across the environment. Which capability is best suited for this task?

  1. Bulk Domain Search
    2. Host Search
    3. User Search
    4. Process Tree

Correct Answer: 1. Bulk Domain Search

Explanation:

Bulk Domain Search is intended for investigations involving multiple domain indicators. It allows responders to evaluate a list of domains more efficiently than performing individual searches for each one. This is particularly useful when threat intelligence provides multiple phishing, malware, or command-and-control domains. Host Search focuses on endpoints, User Search focuses on identities, and Process Tree focuses on execution relationships. For a large collection of suspicious domain indicators, Bulk Domain Search provides the most efficient and focused investigative approach.

Question 153.

An analyst needs to identify what a suspicious process launched after it executed. Which process relationship should be reviewed?

  1. Parent process
    2. Child processes
    3. Host group
    4. Sensor version

Correct Answer: 2. Child processes

Explanation:

Child processes are the processes created or launched by another process. Reviewing them allows the analyst to determine what actions followed the execution of a suspicious process. This can reveal command shells, scripts, system utilities, additional malware, or other activity that may be part of an attack chain. The parent process identifies what launched the suspicious process, but not what it started afterward. Host groups and sensor versions provide administrative context rather than execution relationships. Child-process analysis is therefore the correct approach for understanding downstream behavior.

Question 154.

A responder verifies that a file belongs to approved software and should be permitted. Which hash-management action should be selected?

  1. Block
    2. Detect Only
    3. Allow
    4. Block and Hide Detection

Correct Answer: 3. Allow

Explanation:

Allow is appropriate when the responder has verified that a file is legitimate and should be permitted to execute. Before applying the action, the analyst should confirm the hash and file identity carefully to avoid trusting malicious content accidentally. Block prevents execution, while Detect Only continues monitoring without the same prevention effect. Block and Hide Detection combines blocking with a different visibility outcome. When trusted business software needs to run normally, Allow is the hash-management action that most directly meets the requirement.

Question 155.

An analyst wants to search detailed enterprise telemetry related to an existing detection. Which capability should be used?

  1. Event Advanced Search
    2. User role configuration
    3. Host group creation
    4. Sensor update policy

Correct Answer: 1. Event Advanced Search

Explanation:

Event Advanced Search allows analysts to investigate detailed enterprise telemetry beyond the information initially shown in a detection. It can help identify related events, refine search results, and uncover additional evidence connected to suspicious activity. This makes it valuable for determining scope and reconstructing attack sequences. User role configuration, host group creation, and sensor update policies are administrative functions and do not provide detailed telemetry analysis. Event Advanced Search is therefore the appropriate capability for deeper event investigation.

Question 156.

An application repeatedly generates detections but has been confirmed as legitimate. What is the safest approach before creating an exclusion?

  1. Exclude the entire drive
    2. Disable all endpoint prevention
    3. Validate the behavior and use the narrowest appropriate exclusion
    4. Ignore all future alerts from the host

Correct Answer: 3. Validate the behavior and use the narrowest appropriate exclusion

Explanation:

Before creating an exclusion, the responder should verify that the behavior is truly legitimate and understand how the exclusion will affect detection, prevention, or telemetry. The exclusion should be scoped as narrowly as possible to avoid creating unnecessary security blind spots. Excluding an entire drive or disabling endpoint prevention would significantly weaken protection. Ignoring all future alerts could also allow unrelated malicious behavior to go unnoticed. Careful validation and minimal scoping provide the best balance between reducing false positives and maintaining security coverage.

Question 157.

In MITRE ATT&CK, what is the relationship between a tactic and a technique?

  1. A tactic is an objective, while a technique is a method used to achieve it
    2. A tactic is a file hash, while a technique is an IP address
    3. A tactic is a detection status, while a technique is a severity level
    4. A tactic is a user role, while a technique is a host group

Correct Answer: 1. A tactic is an objective, while a technique is a method used to achieve it

Explanation:

MITRE ATT&CK uses tactics to represent high-level adversary objectives and techniques to represent methods used to achieve those objectives. For example, Credential Access is a tactic, while specific credential theft methods are represented as techniques. Understanding this relationship helps responders interpret detections and place suspicious behavior into a broader attack sequence. File hashes, IP addresses, detection statuses, user roles, and host groups are separate security concepts. The tactic-and-technique relationship is fundamental to using ATT&CK effectively during detection analysis.

Question 158.

A security team wants to standardize a recurring sequence of Real Time Response commands. Which solution should be used?

  1. RTR custom script
    2. Sensor visibility exclusion
    3. Detection filter
    4. Domain allowlist

Correct Answer: 1. RTR custom script

Explanation:

An RTR custom script allows approved response commands to be packaged into a reusable workflow. This improves consistency, reduces manual command-entry errors, and can make recurring remediation procedures more efficient. Scripts should be tested carefully and restricted to authorized responders because they can perform significant endpoint actions. Sensor exclusions reduce visibility, detection filters organize alerts, and domain allowlists address different security controls. None of those options standardize a repeated sequence of endpoint response commands. An RTR custom script is therefore the best fit for this requirement.

Question 159.

An analyst suspects that a detection on one system may be related to activity elsewhere. What should the analyst do to determine the scope?

  1. Review only the original detection
    2. Correlate hosts, users, hashes, processes, domains, and IP addresses
    3. Immediately close the detection
    4. Disable endpoint telemetry

Correct Answer: 2. Correlate hosts, users, hashes, processes, domains, and IP addresses

Explanation:

Determining incident scope requires correlating multiple types of evidence across the environment. The analyst should review associated hosts, users, processes, file hashes, domains, IP addresses, timelines, and relevant event data. This can reveal whether the suspicious activity appears on additional systems or involves other accounts. Reviewing only the original detection may miss connected activity, while immediately closing it could leave an incident unresolved. Disabling telemetry would reduce visibility. Correlation across several evidence types provides the strongest basis for understanding the true scope of an incident.

Question 160.

A suspicious process starts several scripts and command-line utilities. What should the analyst review next to understand the activity that followed?

  1. Subscription details
    2. User interface settings
    3. Host naming policy
    4. Child processes and related events

Correct Answer: 4. Child processes and related events

Explanation:

Child processes and related events provide information about what occurred after the suspicious process began executing. Reviewing these events may reveal reconnaissance commands, credential-access behavior, persistence attempts, lateral movement, additional payloads, or other suspicious actions. This information helps reconstruct the attack chain and determine what response may be required. Subscription details, interface settings, and naming policies do not explain endpoint behavior. Examining the downstream child processes and associated events is therefore the most appropriate next step for understanding subsequent activity.