{"id":17529,"date":"2026-09-21T10:05:37","date_gmt":"2026-09-21T10:05:37","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17529"},"modified":"2026-09-21T10:05:37","modified_gmt":"2026-09-21T10:05:37","slug":"crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccfr-201-exam-dumps\"><b>CrowdStrike CCFR-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 101.<\/b><\/p>\n<p><b>An analyst discovers that a suspicious process spawned a command shell and several system utilities. Which view would best help reconstruct this execution chain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host group settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User role settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor update policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Process Tree<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process Tree is designed to display hierarchical relationships between processes, including parents and children. It allows an analyst to determine what launched a suspicious process and what that process subsequently created. In this scenario, reviewing the command shell and system utilities within the tree can help reconstruct the sequence of execution and identify potentially malicious behavior. Host groups, user roles, and sensor update policies provide administrative information rather than execution context. Process Tree is therefore the most appropriate tool for understanding multi-stage process relationships during an endpoint investigation.<\/span><\/p>\n<p><b>Question 102.<\/b><\/p>\n<p><b>A responder identifies a suspicious SHA-256 hash and needs to determine whether the same file exists on other endpoints. What should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Hash Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash Search is used when the investigation begins with a known file hash. It can help responders identify whether the same file has appeared elsewhere across the environment and determine which hosts may be affected. This is particularly useful when scoping malware or suspicious executable activity. IP Search focuses on network addresses, User Search focuses on account activity, and Domain Search focuses on domain indicators. Hash Search is therefore the most direct way to investigate the prevalence and distribution of a suspicious file based on its SHA-256 value.<\/span><\/p>\n<p><b>Question 103.<\/b><\/p>\n<p><b>An analyst needs a broad chronological view of activity occurring on one endpoint before and after a detection. Which capability should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hash management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Host Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host Timeline provides a chronological view of endpoint activity and is useful when an analyst wants to understand what occurred across a system over a period of time. It can reveal events that happened before and after the initial detection and help connect related activity. User Search focuses on identity information, Hash management controls file handling, and Bulk Domain Search is intended for multiple domain indicators. When the investigation requires a broad endpoint-level chronology rather than a single process view, Host Timeline is the most appropriate capability.<\/span><\/p>\n<p><b>Question 104.<\/b><\/p>\n<p><b>A responder must remotely inspect files and execute approved remediation commands on an affected endpoint. Which Falcon capability is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Real Time Response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Real Time Response<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Real Time Response provides authorized responders with direct remote access to supported endpoints for investigation and remediation. Through an RTR session, an analyst can run permitted commands, inspect files, collect information, and perform approved response actions. Detection filters help organize alerts, while User Search and Bulk Domain Search provide investigation context without direct endpoint interaction. Because RTR commands can affect endpoint systems, organizations should control permissions carefully and maintain appropriate auditing. For remote investigation and remediation, Real Time Response is the correct capability.<\/span><\/p>\n<p><b>Question 105.<\/b><\/p>\n<p><b>A suspicious executable is found on only one workstation in an environment containing thousands of endpoints. Which characteristic is being evaluated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detection status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor version<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internal prevalence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internal prevalence describes how common or rare an artifact is within the organization&#8217;s own environment. A file appearing on only one workstation has very low internal prevalence and may deserve additional investigation, particularly if its behavior is also suspicious. However, rarity alone does not prove maliciousness. Analysts should combine prevalence with process behavior, reputation, network activity, and other evidence. Detection status, sensor version, and user role provide different information and do not directly measure how widely a file appears across managed endpoints.<\/span><\/p>\n<p><b>Question 106.<\/b><\/p>\n<p><b>A file hash has been confirmed as malicious and must be prevented from executing while normal detection visibility remains available. Which action should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Block<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Block is the appropriate action when the organization has confirmed that a file represented by a hash is malicious and wants to prevent its execution. This option provides prevention while maintaining detection visibility. Detect Only can preserve detection without applying the same prevention action, while Allow is intended for trusted content. No action does not meet the requirement to prevent execution. Responders should validate the hash carefully before blocking it because an incorrect decision could disrupt legitimate software. Hash-management actions should always reflect the intended security outcome.<\/span><\/p>\n<p><b>Question 107.<\/b><\/p>\n<p><b>An investigation begins with a username suspected of being involved in malicious activity. Which search capability is the best starting point?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User Search is the most suitable starting point when an investigation centers on a specific account. It can provide information associated with that user and help responders identify related systems or activity. From there, the analyst can pivot into detections, endpoint events, processes, or other evidence. Hash Search focuses on files, IP Search focuses on network addresses, and Process Timeline focuses on activity associated with a process. When the known indicator is a username, User Search provides the most direct investigative path.<\/span><\/p>\n<p><b>Question 108.<\/b><\/p>\n<p><b>A detection contains a suspicious IP address believed to be associated with command-and-control activity. Which tool should the analyst use first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IP Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Search is the most appropriate tool when the known indicator is a network address. It can help analysts determine whether endpoints in the environment have communicated with the suspicious IP and identify related activity. This is valuable when investigating potential command-and-control infrastructure or suspicious remote services. User Search focuses on accounts, Process Tree shows process execution relationships, and Hash Search focuses on files. Starting with IP Search allows the responder to gather network-specific context and identify systems that may require further investigation.<\/span><\/p>\n<p><b>Question 109.<\/b><\/p>\n<p><b>An analyst wants to display only unresolved high-severity detections from a large queue. Which feature should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTR custom scripts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hash blocking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor exclusions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Detection filters<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection filters allow analysts to narrow a large queue according to criteria such as severity, status, host, or other available properties. This helps responders focus on the most important alerts without changing endpoint security settings. RTR scripts perform endpoint actions, Hash blocking changes file enforcement, and Sensor exclusions can reduce telemetry or detection coverage. None of those features are intended simply to organize or prioritize the detection queue. Filtering is therefore the correct approach when the analyst needs to focus on unresolved high-severity detections.<\/span><\/p>\n<p><b>Question 110.<\/b><\/p>\n<p><b>An analyst wants to investigate events associated specifically with a suspicious process rather than reviewing all activity on the endpoint. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Process Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process Timeline provides a focused chronological view of activity associated with a particular process. It is useful when the analyst has already identified a suspicious executable and wants to understand its behavior without reviewing every unrelated event on the endpoint. Host Timeline provides broader host-wide context, while User Search and Bulk Domain Search investigate different types of indicators. When the investigation is centered on one process, Process Timeline is the most appropriate tool for examining related events and understanding the process&#8217;s behavior.<\/span><\/p>\n<p><b>Question 111.<\/b><\/p>\n<p><b>A manager asks which responder executed a particular command during an RTR session. Where should the analyst look?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTR audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. RTR audit logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RTR audit logs provide records of actions performed during Real Time Response sessions. They support accountability by allowing security teams to review who initiated actions and what occurred during remote response activity. Process Tree displays endpoint execution relationships, while detection severity helps prioritize alerts and internal prevalence shows how common an artifact is. None of those sources identify the responder responsible for RTR commands. Audit information is therefore the appropriate place to verify command execution and user activity during RTR sessions.<\/span><\/p>\n<p><b>Question 112.<\/b><\/p>\n<p><b>A threat intelligence report contains dozens of suspicious domains. Which capability allows the responder to investigate them most efficiently?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Bulk Domain Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk Domain Search is designed to efficiently investigate multiple domain indicators. It allows responders to evaluate a list of suspicious domains without manually searching each one through separate workflows. This is particularly useful when threat intelligence identifies phishing, malware-delivery, or command-and-control domains. Host Timeline focuses on activity from one endpoint, User Search focuses on account activity, and Process Tree focuses on process relationships. When the investigation begins with many domains, Bulk Domain Search provides the most efficient method for identifying possible matches in the environment.<\/span><\/p>\n<p><b>Question 113.<\/b><\/p>\n<p><b>A suspicious process was launched by an unexpected application. Which process relationship helps identify the application that started it?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sibling process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Parent process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The parent process identifies the process responsible for launching another process. Reviewing it can help analysts determine how suspicious execution began and reveal abnormal relationships, such as an office application spawning a command shell. Child processes show activity launched afterward, while sibling processes share a common parent but do not directly identify what launched the suspicious executable. Host groups are administrative constructs rather than execution relationships. Examining the parent process is therefore the most direct method for identifying the application that initiated the suspicious process.<\/span><\/p>\n<p><b>Question 114.<\/b><\/p>\n<p><b>An analyst has verified that a file belongs to trusted software and should be permitted to execute. Which hash-management action is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Block and Hide Detection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Allow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Allow is appropriate when a file has been positively verified as trusted and should be permitted according to organizational policy. The responder should confirm the hash carefully before selecting this action because incorrectly allowing malicious software could reduce protection. Block prevents execution, while Detect Only continues monitoring without applying the same prevention behavior. Block and Hide Detection is intended for a different security outcome. For confirmed legitimate software that should execute normally, Allow is the hash-management option that best matches the requirement.<\/span><\/p>\n<p><b>Question 115.<\/b><\/p>\n<p><b>An analyst wants to expand a detection investigation into detailed enterprise telemetry and search for related events. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Event Advanced Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host group creation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor uninstall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash Allow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Event Advanced Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Event Advanced Search allows responders to examine detailed event telemetry beyond the initial detection. It can be used to search for related activity, refine results, and identify additional evidence connected to suspicious behavior. This helps analysts determine incident scope and reconstruct the sequence of events. Host group creation and sensor uninstall are administrative actions, while Hash Allow changes how a file is treated. None of those functions provide the detailed event investigation capability offered by Event Advanced Search.<\/span><\/p>\n<p><b>Question 116.<\/b><\/p>\n<p><b>A legitimate application repeatedly causes unwanted detections. What should the responder do before creating an exclusion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude the entire endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Validate the behavior and choose the narrowest suitable exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all prevention policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore every future detection from the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Validate the behavior and choose the narrowest suitable exclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before creating an exclusion, the responder should verify that the activity is genuinely legitimate and understand the effect of the proposed exclusion type. The scope should be as narrow as possible so that unrelated malicious activity remains visible and protected. Excluding an entire endpoint or disabling prevention would unnecessarily weaken security. Ignoring all future detections is also unsafe because behavior may change. Careful validation and limited scoping help reduce false positives while preserving as much protection and investigative visibility as possible.<\/span><\/p>\n<p><b>Question 117.<\/b><\/p>\n<p><b>Within MITRE ATT&amp;CK, which element represents the method an adversary uses to achieve an objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Tactic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Technique<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Technique<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In MITRE ATT&amp;CK, techniques describe methods adversaries use to accomplish their objectives. Tactics represent the higher-level objectives, such as Persistence, Credential Access, Discovery, or Exfiltration. A technique explains how an attacker may pursue one of those goals. Understanding the relationship between tactics and techniques helps responders interpret ATT&amp;CK mappings and place suspicious endpoint behavior into a broader attack context. Severity and policy are separate security concepts and are not ATT&amp;CK elements describing adversary methods.<\/span><\/p>\n<p><b>Question 118.<\/b><\/p>\n<p><b>A security team wants to reuse the same sequence of approved RTR commands during recurring incidents. What is the most appropriate solution?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create an RTR custom script<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create a broad sensor exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Change detection severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create a user group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Create an RTR custom script<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An RTR custom script allows a security team to package a repeatable sequence of response commands into a reusable workflow. This can improve consistency, reduce manual typing, and lower the chance of errors during recurring remediation tasks. Scripts should be tested and restricted to authorized responders because they may perform significant actions on endpoints. Sensor exclusions affect visibility, while changing detection severity or creating user groups does not perform remediation. A custom RTR script is therefore the most appropriate solution for standardized recurring response procedures.<\/span><\/p>\n<p><b>Question 119.<\/b><\/p>\n<p><b>An analyst must determine whether suspicious activity seen on one endpoint is part of a wider incident. Which approach provides the strongest investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review only the original detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Correlate hosts, users, hashes, processes, and network indicators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Immediately close the detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable telemetry collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Correlate hosts, users, hashes, processes, and network indicators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Determining incident scope requires correlating multiple sources of evidence. The analyst should examine related hosts, user accounts, process relationships, file hashes, network indicators, timelines, and relevant event data. This helps identify whether the same behavior or indicators appear elsewhere in the environment. Reviewing only the initial detection may miss related compromise, while closing the detection prematurely could leave malicious activity unresolved. Disabling telemetry would reduce visibility. Correlating several evidence types provides the strongest basis for determining whether an incident is isolated or widespread.<\/span><\/p>\n<p><b>Question 120.<\/b><\/p>\n<p><b>A suspicious executable launches several command-line utilities and scripts. What should the analyst investigate next to understand downstream behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Child processes and related event activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Console display settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Subscription configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host naming convention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Child processes and related event activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes and related events reveal what happened after the suspicious executable started. Reviewing them may expose reconnaissance commands, credential access attempts, persistence mechanisms, lateral movement activity, or other malicious behavior. This information helps the analyst reconstruct the execution chain and determine the scope and severity of the incident. Console settings, subscription configuration, and host naming conventions do not explain endpoint behavior. Investigating downstream child processes and associated events is therefore the most appropriate next step in the analysis.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps &nbsp; Question 101. An analyst discovers that a suspicious process spawned a command shell and several system utilities. Which view would best help reconstruct this execution chain? Process Tree 2. Host group settings 3. User role settings 4. Sensor update policy Correct Answer: 1. Process [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17529"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17529"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17529\/revisions"}],"predecessor-version":[{"id":17530,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17529\/revisions\/17530"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}