Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free CrowdStrike CCFR-201 Practice Exam with Questions & Answers

Questions 1

When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?

Options:
A.

It contains an internal value not useful for an investigation

B.

It contains the TargetProcessld_decimal value of the child process

C.

It contains the Sensorld_decimal value for related events

D.

It contains the TargetProcessld_decimal of the parent process

CrowdStrike CCFR-201 Premium Access
Questions 2

Which statement is TRUE regarding the "Bulk Domains" search?

Options:
A.

It will show a list of computers and process that performed a lookup of any of the domains in your search

B.

The "Bulk Domains" search will allow you to blocklist your queried domains

C.

The "Bulk Domains" search will show IP address and port information for any associated connectionsD.You should only pivot to the "Bulk Domains" search tool after completing an investigation

Questions 3

How long are quarantined files stored in the CrowdStrike Cloud?

Options:
A.

45 Days

B.

90 Days

C.

Days

D.

Quarantined files are not deleted

Questions 4

You receive an email from a third-party vendor that one of their services is compromised,thevendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?

Options:
A.

IP Addresses

B.

Remote or Network Logon Activity

C.

Remote Access Graph

D.

Hash Executions

Questions 5

What information is contained within a Process Timeline?

Options:
A.

All cloudable process-related events within a given timeframe

B.

All cloudable events for a specific host

C.

Only detection process-related events within a given timeframe

D.

A view of activities on Mac or Linux hosts

Questions 6

A list of managed and unmanaged neighbors for an endpoint can be found:

Options:
A.

by using Hosts page in the Investigate tool

B.

by reviewing "Groups" in Host Management under the Hosts page

C.

under "Audit" by running Sensor Visibility Exclusions Audit

D.

only by searching event data using Event Search

Questions 7

What information does the MITRE ATT&CK®Framework provide?

Options:
A.

It provides best practices for different cybersecurity domains, such as Identify and Access Management

B.

It provides a step-by-step cyber incident response strategy

C.

It provides the phases of an adversary's lifecycle, the platforms they are known to attack, and the specific methods they use

D.

It is a system that attributes an attack techniques to a specific threat actor

Questions 8

Where can you find hosts that are in Reduced Functionality Mode?

Options:
A.

Event Search

B.

Executive Summary dashboard

C.

Host Search

D.

Installation Tokens

Questions 9

When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?

Options:
A.

It contains the TargetProcessld_decimal value for other related events

B.

It contains an internal value not useful for an investigation

C.

It contains the ContextProcessld_decimal value for the parent process that made the DNS request

D.

It contains the TargetProcessld_decimal value for the process that made the DNS request

Questions 10

What are Event Actions?

Options:
A.

Automated searches that can be used to pivot between related events and searches

B.

Pivotable hyperlinks available in a Host Search

C.

Custom event data queries bookmarked by the currently signed in Falcon user

D.

Raw Falcon event data

Exam Code: CCFR-201
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Certified Falcon Responder
Last Update: Jul 12, 2025
Questions: 60
PDF + Testing Engine
$164.99
$57.75
Testing Engine
$124.99
$43.75
PDF (Q&A)
$104.99
$36.75

CrowdStrike Free Exams

CrowdStrike Free Exams
Examstrack provides free CrowdStrike exam prep materials and practice tests to support your CrowdStrike certification goals.