{"id":17533,"date":"2026-09-21T10:06:13","date_gmt":"2026-09-21T10:06:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17533"},"modified":"2026-09-21T10:06:13","modified_gmt":"2026-09-21T10:06:13","slug":"crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccfr-201-exam-dumps\"><b>CrowdStrike CCFR-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 141.<\/b><\/p>\n<p><b>An analyst reviewing suspicious execution needs to determine what launched a command interpreter. Which process relationship should be examined first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sibling process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Parent process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The parent process identifies the process that directly launched another process. Reviewing it helps the analyst understand how suspicious execution began and can expose unusual process relationships, such as a document application launching a command interpreter. Child processes show what the suspicious process started afterward, while sibling processes share a common parent but do not identify the direct launcher. Host groups are administrative constructs rather than execution relationships. Examining the parent process is therefore the most direct way to determine the origin of a suspicious process during an investigation.<\/span><\/p>\n<p><b>Question 142.<\/b><\/p>\n<p><b>A responder has a SHA-256 value for a suspicious executable and wants to identify other systems where it has appeared. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Hash Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash Search is designed for investigations that begin with a file hash. It can help responders determine whether the same executable has appeared on other endpoints and identify potentially affected systems. This is useful for determining whether malicious activity is isolated or widespread. User Search focuses on identities, IP Search investigates network addresses, and Host Timeline provides chronological activity for a host. When the known indicator is a SHA-256 hash, Hash Search is the most direct and efficient method for locating related file activity across the environment.<\/span><\/p>\n<p><b>Question 143.<\/b><\/p>\n<p><b>An analyst wants to examine a complete chronological sequence of events on an endpoint during a suspected intrusion. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Host Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host Timeline provides chronological activity across an endpoint and is useful for reconstructing what occurred during a suspected intrusion. The analyst can review events that happened before and after suspicious behavior and identify related activity that may not be visible in the original detection. Process Tree focuses on process relationships rather than complete host chronology. User Search focuses on identity activity, and hash management controls file actions. When the investigation requires a broad time-based view across the entire endpoint, Host Timeline is the most suitable capability.<\/span><\/p>\n<p><b>Question 144.<\/b><\/p>\n<p><b>A responder needs to remotely collect information and execute approved commands on a compromised endpoint. Which Falcon capability should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Real Time Response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Real Time Response<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Real Time Response provides authorized responders with remote interaction capabilities for supported endpoints. Through RTR, the analyst can execute approved commands, inspect files, collect information, and perform remediation actions without physically accessing the device. Bulk Domain Search investigates domain indicators, Detection filters organize alerts, and Hash Search focuses on files across the environment. Those capabilities do not provide direct endpoint control. Because RTR can affect endpoint systems, access should be limited to authorized responders and activity should be reviewed through appropriate audit records.<\/span><\/p>\n<p><b>Question 145.<\/b><\/p>\n<p><b>A file appears on nearly every workstation in the organization. Which characteristic is the analyst evaluating?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ATT&amp;CK tactic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internal prevalence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internal prevalence describes how commonly a file or artifact appears within the organization&#8217;s own environment. A file present on nearly every workstation has very high internal prevalence. This can provide useful investigative context, although high prevalence alone does not prove that a file is legitimate. Analysts should also evaluate reputation, behavior, process relationships, and other evidence. Detection severity and ATT&amp;CK tactics describe different security concepts, while user roles control access. Internal prevalence is therefore the correct factor for measuring how widespread a file is across enterprise systems.<\/span><\/p>\n<p><b>Question 146.<\/b><\/p>\n<p><b>A malicious file hash has been confirmed and the organization wants to stop the associated file from executing. Which action is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Block<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Block is the appropriate hash-management action when a file is confirmed as malicious and should be prevented from executing. Detect Only maintains detection visibility but does not provide the same blocking behavior. Allow is intended for trusted software, while No action does not meet the requirement to prevent execution. Before blocking a hash, the responder should verify that the value corresponds to the intended malicious file because an incorrect block could affect legitimate applications. Hash-management actions should always be selected according to the required prevention and visibility outcome.<\/span><\/p>\n<p><b>Question 147.<\/b><\/p>\n<p><b>An analyst is investigating suspicious activity tied to a particular employee account. Which search provides the best starting point?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User Search is the most appropriate starting point when the investigation centers on a particular user account. It can provide identity-related information and help the analyst identify systems or activity associated with that account. The responder can then pivot into detections, endpoint events, process relationships, or network indicators as needed. Hash Search focuses on files, IP Search focuses on network addresses, and Process Tree focuses on execution relationships. Starting with User Search keeps the investigation aligned with the known identity indicator.<\/span><\/p>\n<p><b>Question 148.<\/b><\/p>\n<p><b>A suspicious external IP address is associated with several alerts. Which search capability should the responder use to investigate it?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IP Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Search is designed for investigations centered on network addresses. It can help the responder identify related activity, determine whether multiple endpoints communicated with the suspicious IP, and assess the possible scope of network-based activity. Hash Search focuses on files, Process Timeline focuses on a particular process, and User Search focuses on identity activity. When the known indicator is an external IP address, IP Search provides the most direct route to additional network context and related endpoint evidence.<\/span><\/p>\n<p><b>Question 149.<\/b><\/p>\n<p><b>An analyst wants to display only open critical detections from a specific group of endpoints. What should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTR scripts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor exclusions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash allowlisting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Detection filters<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection filters allow responders to narrow detection queues using criteria such as status, severity, host, or host group. This helps analysts quickly focus on the alerts most relevant to the investigation without altering endpoint protection settings. RTR scripts perform response actions, sensor exclusions can reduce security visibility, and hash allowlisting changes how trusted files are handled. None of these features are intended simply to organize a detection queue. Filtering is therefore the correct approach when the analyst needs to focus on open critical detections from selected endpoints.<\/span><\/p>\n<p><b>Question 150.<\/b><\/p>\n<p><b>An analyst wants to focus on events related to one suspicious process rather than all events occurring on the host. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Process Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process Timeline provides a focused chronological view of events associated with a specific process. It is particularly useful when the analyst has already identified the suspicious executable and wants to understand its behavior without reviewing unrelated host activity. Host Timeline provides broader endpoint context, while User Search and Bulk Domain Search investigate identities and domains. By using Process Timeline, the responder can concentrate on events that are directly relevant to the process and better understand its actions within the attack chain.<\/span><\/p>\n<p><b>Question 151.<\/b><\/p>\n<p><b>A security administrator needs to confirm which user executed commands through Real Time Response during an incident. What should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTR audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detection grouping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RTR audit logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RTR audit logs provide records of actions performed during Real Time Response sessions. They allow security teams to review which authorized user performed specific commands and help support incident documentation, accountability, troubleshooting, and compliance. Process Tree displays endpoint execution relationships, internal prevalence measures how common an artifact is, and detection grouping organizes alerts. None of those sources provide an administrative audit trail for RTR activity. RTR audit logs are therefore the correct place to verify responder actions during an incident.<\/span><\/p>\n<p><b>Question 152.<\/b><\/p>\n<p><b>A responder receives a list of many suspicious domains and wants to check them efficiently across the environment. Which capability is best suited for this task?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Bulk Domain Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk Domain Search is intended for investigations involving multiple domain indicators. It allows responders to evaluate a list of domains more efficiently than performing individual searches for each one. This is particularly useful when threat intelligence provides multiple phishing, malware, or command-and-control domains. Host Search focuses on endpoints, User Search focuses on identities, and Process Tree focuses on execution relationships. For a large collection of suspicious domain indicators, Bulk Domain Search provides the most efficient and focused investigative approach.<\/span><\/p>\n<p><b>Question 153.<\/b><\/p>\n<p><b>An analyst needs to identify what a suspicious process launched after it executed. Which process relationship should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor version<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Child processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes are the processes created or launched by another process. Reviewing them allows the analyst to determine what actions followed the execution of a suspicious process. This can reveal command shells, scripts, system utilities, additional malware, or other activity that may be part of an attack chain. The parent process identifies what launched the suspicious process, but not what it started afterward. Host groups and sensor versions provide administrative context rather than execution relationships. Child-process analysis is therefore the correct approach for understanding downstream behavior.<\/span><\/p>\n<p><b>Question 154.<\/b><\/p>\n<p><b>A responder verifies that a file belongs to approved software and should be permitted. Which hash-management action should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Block and Hide Detection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Allow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Allow is appropriate when the responder has verified that a file is legitimate and should be permitted to execute. Before applying the action, the analyst should confirm the hash and file identity carefully to avoid trusting malicious content accidentally. Block prevents execution, while Detect Only continues monitoring without the same prevention effect. Block and Hide Detection combines blocking with a different visibility outcome. When trusted business software needs to run normally, Allow is the hash-management action that most directly meets the requirement.<\/span><\/p>\n<p><b>Question 155.<\/b><\/p>\n<p><b>An analyst wants to search detailed enterprise telemetry related to an existing detection. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Event Advanced Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User role configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group creation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor update policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Event Advanced Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Event Advanced Search allows analysts to investigate detailed enterprise telemetry beyond the information initially shown in a detection. It can help identify related events, refine search results, and uncover additional evidence connected to suspicious activity. This makes it valuable for determining scope and reconstructing attack sequences. User role configuration, host group creation, and sensor update policies are administrative functions and do not provide detailed telemetry analysis. Event Advanced Search is therefore the appropriate capability for deeper event investigation.<\/span><\/p>\n<p><b>Question 156.<\/b><\/p>\n<p><b>An application repeatedly generates detections but has been confirmed as legitimate. What is the safest approach before creating an exclusion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude the entire drive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all endpoint prevention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Validate the behavior and use the narrowest appropriate exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore all future alerts from the host<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Validate the behavior and use the narrowest appropriate exclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before creating an exclusion, the responder should verify that the behavior is truly legitimate and understand how the exclusion will affect detection, prevention, or telemetry. The exclusion should be scoped as narrowly as possible to avoid creating unnecessary security blind spots. Excluding an entire drive or disabling endpoint prevention would significantly weaken protection. Ignoring all future alerts could also allow unrelated malicious behavior to go unnoticed. Careful validation and minimal scoping provide the best balance between reducing false positives and maintaining security coverage.<\/span><\/p>\n<p><b>Question 157.<\/b><\/p>\n<p><b>In MITRE ATT&amp;CK, what is the relationship between a tactic and a technique?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A tactic is an objective, while a technique is a method used to achieve it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A tactic is a file hash, while a technique is an IP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A tactic is a detection status, while a technique is a severity level<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A tactic is a user role, while a technique is a host group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A tactic is an objective, while a technique is a method used to achieve it<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MITRE ATT&amp;CK uses tactics to represent high-level adversary objectives and techniques to represent methods used to achieve those objectives. For example, Credential Access is a tactic, while specific credential theft methods are represented as techniques. Understanding this relationship helps responders interpret detections and place suspicious behavior into a broader attack sequence. File hashes, IP addresses, detection statuses, user roles, and host groups are separate security concepts. The tactic-and-technique relationship is fundamental to using ATT&amp;CK effectively during detection analysis.<\/span><\/p>\n<p><b>Question 158.<\/b><\/p>\n<p><b>A security team wants to standardize a recurring sequence of Real Time Response commands. Which solution should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTR custom script<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Sensor visibility exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detection filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Domain allowlist<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RTR custom script<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An RTR custom script allows approved response commands to be packaged into a reusable workflow. This improves consistency, reduces manual command-entry errors, and can make recurring remediation procedures more efficient. Scripts should be tested carefully and restricted to authorized responders because they can perform significant endpoint actions. Sensor exclusions reduce visibility, detection filters organize alerts, and domain allowlists address different security controls. None of those options standardize a repeated sequence of endpoint response commands. An RTR custom script is therefore the best fit for this requirement.<\/span><\/p>\n<p><b>Question 159.<\/b><\/p>\n<p><b>An analyst suspects that a detection on one system may be related to activity elsewhere. What should the analyst do to determine the scope?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review only the original detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Correlate hosts, users, hashes, processes, domains, and IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Immediately close the detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Correlate hosts, users, hashes, processes, domains, and IP addresses<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Determining incident scope requires correlating multiple types of evidence across the environment. The analyst should review associated hosts, users, processes, file hashes, domains, IP addresses, timelines, and relevant event data. This can reveal whether the suspicious activity appears on additional systems or involves other accounts. Reviewing only the original detection may miss connected activity, while immediately closing it could leave an incident unresolved. Disabling telemetry would reduce visibility. Correlation across several evidence types provides the strongest basis for understanding the true scope of an incident.<\/span><\/p>\n<p><b>Question 160.<\/b><\/p>\n<p><b>A suspicious process starts several scripts and command-line utilities. What should the analyst review next to understand the activity that followed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Subscription details<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User interface settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host naming policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Child processes and related events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Child processes and related events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes and related events provide information about what occurred after the suspicious process began executing. Reviewing these events may reveal reconnaissance commands, credential-access behavior, persistence attempts, lateral movement, additional payloads, or other suspicious actions. This information helps reconstruct the attack chain and determine what response may be required. Subscription details, interface settings, and naming policies do not explain endpoint behavior. Examining the downstream child processes and associated events is therefore the most appropriate next step for understanding subsequent activity.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps &nbsp; Question 141. An analyst reviewing suspicious execution needs to determine what launched a command interpreter. Which process relationship should be examined first? Parent process 2. Child process 3. Sibling process 4. Host group Correct Answer: 1. Parent process Explanation: The parent process identifies the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17533"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17533"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17533\/revisions"}],"predecessor-version":[{"id":17534,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17533\/revisions\/17534"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}