{"id":17553,"date":"2026-09-21T10:11:01","date_gmt":"2026-09-21T10:11:01","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17553"},"modified":"2026-09-21T10:11:01","modified_gmt":"2026-09-21T10:11:01","slug":"crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part18-q361-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part18-q361-340\/","title":{"rendered":"CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part18 Q361-340\u00a0"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccfr-201-exam-dumps\"><b>CrowdStrike CCFR-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p><b>Question 341.<\/b><\/p>\n<p><b>An analyst sees a suspicious command-line process and wants to determine which application launched it. Which relationship should be examined first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Parent process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The parent process identifies the process that directly launched another process. Reviewing it helps analysts determine how suspicious execution began and can expose abnormal relationships, such as a document application or browser launching a command-line interpreter. Child processes show what the suspicious process launched afterward, while host groups and sensor policies provide administrative rather than execution context. Examining the parent process is therefore the most direct method for identifying the origin of suspicious activity and reconstructing the beginning of the execution chain.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>A responder has identified a suspicious file hash and wants to determine whether the same file appears on additional endpoints. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Hash Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash Search allows responders to investigate a known file hash across the environment. It can help identify additional endpoints where the file has appeared and determine whether suspicious activity is isolated or more widespread. User Search focuses on identities, IP Search focuses on network addresses, and Process Timeline examines activity associated with a specific process. When the investigation begins with a file hash, Hash Search provides the most direct way to locate related systems and understand the artifact&#8217;s presence across the organization.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>An analyst needs to review endpoint activity in chronological order around the time of a suspicious detection. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Host Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host Timeline provides a chronological view of activity across an endpoint. It can help analysts understand what occurred before, during, and after suspicious behavior and reveal related events that may not be obvious from the initial detection. Process Tree focuses on process relationships rather than complete host chronology. User Search focuses on account activity, while hash management controls file actions. When broad endpoint-level chronological context is required, Host Timeline is the most appropriate investigative capability.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>An authorized responder needs to remotely inspect files and execute approved remediation commands on an affected endpoint. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Real Time Response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Real Time Response<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Real Time Response enables authorized responders to interact directly with supported endpoints. Through RTR, they can execute approved commands, inspect files, gather evidence, and perform remediation remotely. Detection filters organize alerts, while Bulk Domain Search and User Search provide investigative context without direct endpoint control. Because RTR can make significant changes to systems, access should be tightly controlled and actions should be auditable. RTR is therefore the correct capability when active remote investigation or remediation is required.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>A suspicious executable appears on only one endpoint in a large enterprise. Which concept best describes this observation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host containment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internal prevalence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internal prevalence describes how common or rare an artifact is within an organization&#8217;s environment. A file observed on only one endpoint has low internal prevalence and may warrant additional investigation when combined with suspicious behavior. Low prevalence alone does not prove maliciousness, so analysts should also examine process behavior, reputation, network activity, and related detections. Detection severity, containment status, and user privilege describe different security properties and do not measure how widely a file appears across systems.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>A file hash has been confirmed as malicious and must be prevented from executing. Which hash-management action should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Block<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Block is appropriate when a file hash has been confirmed as malicious and the organization wants to prevent the associated file from executing. Detect Only preserves monitoring without providing the same prevention behavior, while Allow is intended for trusted files. No action does not satisfy the prevention requirement. Responders should validate the hash carefully before applying a block to avoid disrupting legitimate software. The selected hash-management action should align with both the confidence of the investigation and the desired security outcome.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>An analyst is investigating suspicious activity associated with a particular username. Which capability should be used first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User Search is the appropriate starting point when an investigation centers on a specific account. It can help responders identify activity and systems associated with that identity and provide context for pivots into detections, processes, hosts, or network indicators. Hash Search focuses on files, IP Search focuses on network addresses, and Process Tree focuses on execution relationships. When the known starting indicator is a username, User Search provides the most direct identity-focused investigative approach.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>A suspicious external IP address is found in endpoint telemetry. Which capability should be used to investigate related activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IP Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Search is designed for investigations involving network addresses. It can help determine whether endpoints communicated with the suspicious IP and identify related activity across the environment. This is useful when investigating potential command-and-control infrastructure or suspicious remote services. Hash Search focuses on file artifacts, User Search focuses on identities, and Process Timeline focuses on a particular process. IP Search therefore provides the most relevant network-focused context for investigating a suspicious address.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>An analyst needs to focus a large detection queue on unresolved high-severity items. Which feature should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTR custom scripts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor exclusions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash Allow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Detection filters<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection filters allow responders to narrow large detection queues using criteria such as severity, status, host, or other available properties. Filtering for unresolved high-severity detections helps prioritize the most urgent items without changing endpoint protection controls. RTR scripts execute response actions, sensor exclusions can reduce visibility, and hash actions modify file handling. None of those capabilities is intended simply to organize alerts. Detection filtering is therefore the correct approach for focusing on a high-priority subset during triage.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>An analyst wants a chronological view focused only on one suspicious executable. Which capability should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Process Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process Timeline provides a focused chronological view centered on a specific process and its associated activity. It is useful when the analyst has already identified a suspicious executable and wants to investigate its behavior without reviewing unrelated host events. Host Timeline provides broader endpoint-wide context, while User Search and Bulk Domain Search focus on different indicator types. Process Timeline therefore offers the most targeted view for understanding the behavior and surrounding events of one suspicious process.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>A security manager wants to verify which responder executed commands during a Real Time Response session. Which records should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTR audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RTR audit logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RTR audit logs provide records of actions performed during Real Time Response sessions. They can help identify which authorized responder executed specific commands and support accountability, incident documentation, troubleshooting, and compliance. Internal prevalence measures how common an artifact is, Process Tree shows execution relationships, and detection severity helps prioritize alerts. None of those sources provides the administrative audit trail associated with RTR activity. Reviewing RTR audit logs is therefore the appropriate method for verifying responder actions.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>A threat intelligence feed contains numerous suspicious domains. Which capability is most efficient for investigating them together?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Bulk Domain Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk Domain Search is designed for investigations involving multiple domain indicators. It allows responders to evaluate many suspicious domains more efficiently than searching each one separately. This is useful when threat intelligence provides domains associated with phishing, malware delivery, or command-and-control infrastructure. Host Timeline and Process Tree focus on endpoint activity, while User Search focuses on identity activity. Bulk Domain Search is therefore the most appropriate capability for investigating a large set of domain indicators.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>A suspicious process launches scripts, command-line utilities, and additional executables. Which relationship should the analyst examine to understand downstream activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Child processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes show which processes were launched by another process. Reviewing them helps analysts understand what happened after the suspicious process started and may reveal command shells, scripts, reconnaissance tools, credential-access utilities, or additional payloads. The parent process explains what launched the original process, while host groups and sensor policies provide administrative context. Child-process analysis is therefore essential for understanding downstream execution and reconstructing the progression of suspicious activity.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>A responder verifies that an executable is trusted enterprise software and should be permitted to run. Which hash-management action is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Block and Hide Detection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Allow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Allow is appropriate when a file has been verified as trusted and should execute normally according to organizational policy. The responder should carefully validate the file and hash before applying this action because mistakenly allowing malicious content could weaken protection. Block prevents execution, while Detect Only provides monitoring without the same blocking behavior. Block and Hide Detection produces a different prevention and visibility outcome. For confirmed legitimate software, Allow is the appropriate hash-management action.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>An analyst wants to investigate detailed enterprise event telemetry related to an existing detection. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Event Advanced Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host group configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor update policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User role management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Event Advanced Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Event Advanced Search enables responders to investigate detailed telemetry beyond what is initially displayed in a detection. Analysts can search for related events, refine results, and uncover additional evidence that may help determine the scope and sequence of suspicious activity. Host groups, sensor policies, and user roles are administrative functions rather than investigative search tools. When deeper event-level analysis is required, Event Advanced Search provides the appropriate functionality for expanding an investigation.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>A legitimate application repeatedly generates unwanted detections. What is the safest approach before creating an exclusion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude the entire endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable prevention globally<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Verify the behavior and use the narrowest effective exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore all future alerts from the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Verify the behavior and use the narrowest effective exclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before creating an exclusion, the responder should confirm that the activity is genuinely legitimate and understand how the exclusion type will affect detection, prevention, or visibility. The scope should be kept as narrow as possible to minimize security blind spots. Excluding an entire endpoint or disabling prevention globally would weaken security significantly. Ignoring future alerts could also hide unrelated malicious behavior. A carefully validated and narrowly scoped exclusion provides the best balance between reducing false positives and maintaining protection.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>Within MITRE ATT&amp;CK, which concept represents a method adversaries use to achieve a broader objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Tactic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Technique<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detection status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Technique<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A technique in MITRE ATT&amp;CK represents a method or behavior adversaries use to achieve a broader objective. Tactics represent the high-level goals, such as Execution, Persistence, Credential Access, or Discovery. Techniques explain how attackers may accomplish those goals. Understanding the relationship between tactics and techniques helps responders interpret ATT&amp;CK mappings and connect observed behavior to a larger attack sequence. Detection status and host policies are separate operational concepts and do not represent adversary methods.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>A response team wants to standardize a frequently repeated sequence of approved RTR commands. What should be created?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An RTR custom script<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A sensor visibility exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A detection filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A host group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. An RTR custom script<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An RTR custom script allows a repeated sequence of approved commands to be packaged into a reusable response workflow. This improves consistency, reduces manual command-entry errors, and can make recurring remediation procedures more efficient. Scripts should be tested carefully and restricted to authorized responders because they may perform significant endpoint actions. Sensor exclusions affect visibility, detection filters organize alerts, and host groups organize endpoints. An RTR custom script is therefore the most appropriate solution for standardizing repeated response actions.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>An analyst suspects suspicious activity observed on one endpoint may also exist elsewhere in the environment. Which approach is best for determining scope?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review only the original detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Correlate hosts, users, processes, hashes, domains, and IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Close the detection immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable telemetry on unaffected systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Correlate hosts, users, processes, hashes, domains, and IP addresses<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Determining incident scope requires correlating multiple forms of evidence across the environment. Analysts should examine related hosts, users, processes, file hashes, domains, IP addresses, timelines, and event data. This can reveal additional affected systems or accounts and help determine whether suspicious activity extends beyond the original endpoint. Reviewing only one detection may miss connected compromise, while disabling telemetry reduces visibility. Correlating several evidence types provides a stronger basis for understanding the full scope of an incident.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>A suspicious executable launches scripts, network tools, and additional processes. What should the analyst review next to understand subsequent activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Subscription information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Console appearance settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host naming conventions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Child processes and related events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Child processes and related events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes and related events reveal what occurred after the suspicious executable began running. Reviewing them may expose reconnaissance commands, credential-access activity, persistence attempts, additional payloads, or other malicious behavior. This information helps the analyst reconstruct the attack sequence and determine whether further investigation or remediation is required. Subscription information, console appearance settings, and host naming conventions do not explain endpoint execution behavior. Examining downstream process activity and related events is therefore the most appropriate next investigative step.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps Question 341. An analyst sees a suspicious command-line process and wants to determine which application launched it. Which relationship should be examined first? Parent process 2. Child process 3. Host group 4. Sensor policy Correct Answer: 1. Parent process Explanation: The parent process identifies the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17553"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17553"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17553\/revisions"}],"predecessor-version":[{"id":17554,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17553\/revisions\/17554"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}