{"id":17555,"date":"2026-09-21T10:11:33","date_gmt":"2026-09-21T10:11:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17555"},"modified":"2026-09-21T10:11:33","modified_gmt":"2026-09-21T10:11:33","slug":"crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/crowdstrike-ccfr-201-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"CrowdStrike CCFR-201 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccfr-201-exam-dumps\"><b>CrowdStrike CCFR-201 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p><b>Question 361.<\/b><\/p>\n<p><b>An analyst observes that a suspicious scripting process was launched by an unexpected application. Which relationship should be reviewed first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Parent process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The parent process identifies the process that directly launched another process. Reviewing it helps the analyst understand how suspicious execution began and can reveal unusual relationships, such as an office application or browser launching a scripting engine. Child processes show what was launched afterward, while host groups and sensor policies provide administrative context rather than execution details. Examining the parent process is therefore the most direct way to determine the origin of suspicious activity and begin reconstructing the execution chain.<\/span><\/p>\n<p><b>Question 362.<\/b><\/p>\n<p><b>A responder has identified a suspicious file hash and wants to locate other endpoints where the file has appeared. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Hash Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash Search is designed for investigations involving a known file hash. It can help responders identify additional endpoints where the same file has appeared and determine whether suspicious activity is isolated or widespread. User Search focuses on identities, IP Search focuses on network addresses, and Host Timeline provides chronological activity for one endpoint. When the known indicator is a file hash, Hash Search offers the most direct method for locating related systems and expanding the scope of the investigation.<\/span><\/p>\n<p><b>Question 363.<\/b><\/p>\n<p><b>An analyst wants to review activity across an endpoint in chronological order around the time of a detection. Which capability should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Host Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host Timeline provides a chronological view of activity across an endpoint. It can help analysts reconstruct events that occurred before, during, and after suspicious behavior and reveal related activity that may not have been obvious from the original detection. Process Tree focuses on hierarchical process relationships, while User Search and hash management serve different purposes. When broad endpoint-level chronological context is required, Host Timeline is the most appropriate investigative capability.<\/span><\/p>\n<p><b>Question 364.<\/b><\/p>\n<p><b>An authorized responder must remotely investigate a compromised endpoint and execute approved commands. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Real Time Response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Real Time Response<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Real Time Response enables authorized responders to interact directly with supported endpoints. Through RTR, they can execute approved commands, inspect files, gather evidence, and perform remediation remotely. Detection filtering organizes alerts, while Bulk Domain Search and User Search provide investigative context without direct endpoint control. Because RTR can make significant changes to systems, access should be restricted appropriately and actions should be auditable. RTR is therefore the correct capability for active remote investigation and remediation.<\/span><\/p>\n<p><b>Question 365.<\/b><\/p>\n<p><b>A suspicious executable appears on only one endpoint in a large enterprise. Which investigative concept best describes this observation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host containment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internal prevalence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internal prevalence describes how common or rare an artifact is within the organization&#8217;s own environment. A file found on only one endpoint has low internal prevalence and may deserve closer investigation, especially when combined with suspicious behavior. Low prevalence alone does not prove maliciousness, so analysts should also review process activity, reputation, network connections, and related detections. Detection severity, containment status, and user privilege represent different security properties and do not measure how widely a file appears.<\/span><\/p>\n<p><b>Question 366.<\/b><\/p>\n<p><b>A confirmed malicious file must be prevented from executing. Which hash-management action should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No action<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Block<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Block is appropriate when a file hash has been confirmed as malicious and the organization wants to prevent the associated file from executing. Detect Only preserves monitoring without providing the same prevention behavior, while Allow is intended for trusted files. No action does not satisfy the prevention requirement. Responders should validate the hash carefully before applying a block to avoid disrupting legitimate software. The selected hash action should reflect the confidence of the investigation and the desired security outcome.<\/span><\/p>\n<p><b>Question 367.<\/b><\/p>\n<p><b>An investigation begins with a username suspected of being involved in malicious activity. Which capability should be used first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User Search is the appropriate starting point when an investigation centers on a specific account. It can help responders identify activity and systems associated with that identity and provide context for further pivots into detections, processes, hosts, or network indicators. Hash Search focuses on file artifacts, IP Search focuses on network addresses, and Process Tree focuses on execution relationships. When a username is the known starting indicator, User Search provides the most direct identity-focused investigative approach.<\/span><\/p>\n<p><b>Question 368.<\/b><\/p>\n<p><b>A suspicious external IP address appears in endpoint telemetry. Which capability should the analyst use to investigate related communications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hash Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IP Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Search is intended for investigations involving network addresses. It can help identify endpoint activity associated with a suspicious IP and determine whether multiple systems communicated with it. This is useful when investigating potential command-and-control infrastructure or suspicious remote services. Hash Search focuses on files, User Search focuses on identities, and Process Timeline focuses on a particular process. IP Search therefore provides the most relevant network-focused investigative context.<\/span><\/p>\n<p><b>Question 369.<\/b><\/p>\n<p><b>An analyst needs to focus a large detection queue on unresolved high-severity items. Which functionality should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTR custom scripts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor exclusions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hash Allow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Detection filters<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection filters allow responders to narrow large detection queues using criteria such as severity, status, host, or other available properties. Filtering for unresolved high-severity detections helps analysts prioritize the most urgent activity without changing endpoint protection controls. RTR scripts execute response actions, while exclusions and hash actions modify security behavior or visibility. Those capabilities are not intended simply to organize alert queues. Detection filtering is therefore the correct approach for focusing on a high-priority subset.<\/span><\/p>\n<p><b>Question 370.<\/b><\/p>\n<p><b>An analyst wants to review events related only to one suspicious process. Which capability should be selected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Process Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Process Timeline<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process Timeline provides a focused chronological view centered on a specific process and its associated activity. It is useful when the analyst has already identified a suspicious executable and wants to investigate its behavior without reviewing unrelated host events. Host Timeline provides broader endpoint-wide context, while User Search and Bulk Domain Search focus on different indicator types. Process Timeline therefore offers the most targeted view for understanding activity directly associated with one suspicious process.<\/span><\/p>\n<p><b>Question 371.<\/b><\/p>\n<p><b>A security manager wants to verify which responder executed commands during an RTR session. What should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTR audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Internal prevalence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detection severity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RTR audit logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RTR audit logs provide records of actions performed during Real Time Response sessions. They can help identify which authorized responder executed specific commands and support accountability, incident documentation, troubleshooting, and compliance. Internal prevalence measures how common an artifact is, Process Tree shows execution relationships, and detection severity helps prioritize alerts. None of those sources provides the same administrative audit trail. RTR audit logs are therefore the appropriate source for verifying responder activity.<\/span><\/p>\n<p><b>Question 372.<\/b><\/p>\n<p><b>A threat intelligence feed includes dozens of suspicious domains. Which capability is most efficient for investigating them together?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bulk Domain Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host Timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Process Tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Bulk Domain Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk Domain Search is designed for investigations involving multiple domain indicators. It allows responders to evaluate many suspicious domains more efficiently than searching each one individually. This is especially useful when threat intelligence provides domain lists associated with phishing, malware delivery, or command-and-control infrastructure. Host Timeline and Process Tree focus on endpoint activity, while User Search focuses on identities. Bulk Domain Search is therefore the most appropriate capability for handling a large set of domain indicators.<\/span><\/p>\n<p><b>Question 373.<\/b><\/p>\n<p><b>A suspicious process launches scripts, command-line utilities, and additional executables. Which relationship should be examined to understand downstream activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Parent process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Child processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Sensor policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Child processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes show which processes were launched by another process. Reviewing them helps analysts understand what happened after the suspicious process started and may reveal command shells, scripts, reconnaissance tools, credential-access utilities, or additional payloads. The parent process explains what launched the original process, while host groups and sensor policies provide administrative context. Child-process analysis is therefore essential for understanding downstream execution and reconstructing the progression of suspicious activity.<\/span><\/p>\n<p><b>Question 374.<\/b><\/p>\n<p><b>A responder verifies that an executable is trusted enterprise software and should be permitted to run. Which hash-management action is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detect Only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Block and Hide Detection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Allow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Allow is appropriate when a file has been verified as trusted and should execute normally according to organizational policy. The responder should carefully validate the file and hash before applying this action because mistakenly allowing malicious content could weaken security. Block prevents execution, while Detect Only provides monitoring without the same prevention behavior. Block and Hide Detection produces a different prevention and visibility outcome. For confirmed legitimate software, Allow is the appropriate hash-management action.<\/span><\/p>\n<p><b>Question 375.<\/b><\/p>\n<p><b>An analyst wants to investigate detailed enterprise event telemetry related to an existing detection. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Event Advanced Search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Host group configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Sensor update policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User role management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Event Advanced Search<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Event Advanced Search enables responders to investigate detailed telemetry beyond what is initially displayed in a detection. Analysts can search for related events, refine results, and uncover additional evidence that may help determine the scope and sequence of suspicious activity. Host groups, sensor policies, and user roles are administrative capabilities rather than investigative search tools. When deeper event-level analysis is required, Event Advanced Search provides the appropriate functionality for expanding an investigation.<\/span><\/p>\n<p><b>Question 376.<\/b><\/p>\n<p><b>A legitimate application repeatedly generates unwanted detections. What is the safest approach before creating an exclusion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude the entire endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable prevention globally<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Verify the behavior and use the narrowest effective exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore all future alerts from the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Verify the behavior and use the narrowest effective exclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before creating an exclusion, the responder should confirm that the activity is genuinely legitimate and understand how the exclusion type will affect detection, prevention, or visibility. The scope should be kept as narrow as possible to minimize security blind spots. Excluding an entire endpoint or disabling prevention globally would significantly weaken security. Ignoring future alerts could also hide unrelated malicious behavior. A carefully validated and narrowly scoped exclusion provides the best balance between reducing false positives and maintaining protection.<\/span><\/p>\n<p><b>Question 377.<\/b><\/p>\n<p><b>Within MITRE ATT&amp;CK, which concept represents a high-level adversary objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Tactic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Technique<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detection status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Host policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Tactic<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A tactic in MITRE ATT&amp;CK represents a high-level adversary objective, such as Execution, Persistence, Credential Access, Discovery, or Exfiltration. Techniques describe the specific methods attackers use to achieve those objectives. Understanding this relationship helps responders interpret ATT&amp;CK mappings and connect observed activity to a broader attack sequence. Detection status and host policies are separate operational concepts and do not represent adversary objectives within the ATT&amp;CK framework.<\/span><\/p>\n<p><b>Question 378.<\/b><\/p>\n<p><b>A response team wants to standardize a frequently repeated sequence of approved RTR commands. What should be created?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An RTR custom script<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A sensor visibility exclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A detection filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A host group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. An RTR custom script<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An RTR custom script allows a repeated sequence of approved commands to be packaged into a reusable response workflow. This improves consistency, reduces manual command-entry errors, and can make recurring remediation procedures more efficient. Scripts should be tested carefully and restricted to authorized responders because they may perform significant endpoint actions. Sensor exclusions affect visibility, detection filters organize alerts, and host groups organize endpoints. An RTR custom script is therefore the most appropriate solution for standardizing repeated response actions.<\/span><\/p>\n<p><b>Question 379.<\/b><\/p>\n<p><b>An analyst suspects suspicious activity observed on one endpoint may also exist elsewhere in the environment. Which approach is best for determining scope?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review only the original detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Correlate hosts, users, processes, hashes, domains, and IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Close the detection immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable telemetry on unaffected systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Correlate hosts, users, processes, hashes, domains, and IP addresses<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Determining incident scope requires correlating multiple forms of evidence across the environment. Analysts should examine related hosts, users, processes, file hashes, domains, IP addresses, timelines, and event data. This can reveal additional affected systems or accounts and help determine whether suspicious activity extends beyond the original endpoint. Reviewing only one detection may miss connected compromise, while disabling telemetry reduces visibility. Correlating several evidence types provides a stronger basis for understanding the full scope of an incident.<\/span><\/p>\n<p><b>Question 380.<\/b><\/p>\n<p><b>A suspicious executable launches scripts, network tools, and additional processes. What should the analyst review next to understand subsequent activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Subscription information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Console appearance settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Host naming conventions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Child processes and related events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Child processes and related events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Child processes and related events reveal what occurred after the suspicious executable began running. Reviewing them may expose reconnaissance commands, credential-access activity, persistence attempts, additional payloads, or other malicious behavior. This information helps the analyst reconstruct the attack sequence and determine whether further investigation or remediation is required. Subscription information, console appearance settings, and host naming conventions do not explain endpoint execution behavior. Examining downstream process activity and related events is therefore the most appropriate next investigative step.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CrowdStrike CCFR-201 Exam Dumps and Practice Test Dumps Question 361. An analyst observes that a suspicious scripting process was launched by an unexpected application. Which relationship should be reviewed first? Parent process 2. Child process 3. Host group 4. Sensor policy Correct Answer: 1. Parent process Explanation: The parent process identifies the process [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17555"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17555"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17555\/revisions"}],"predecessor-version":[{"id":17556,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17555\/revisions\/17556"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}