Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free CrowdStrike CCFR-201b Practice Exam with Questions & Answers | Set: 4

Questions 31

During the incident response process, a responder must update the status of a detection. Which of the following options is NOT a valid detection status recognized by the Falcon console?

Options:
A.

New

B.

Complete

C.

In Progress

D.

True Positive

CrowdStrike CCFR-201b Premium Access
Questions 32

When is a SyntheticProcessRollup2 event type found?

Options:
A.

When events are combined with analyst-found contextual information

B.

When events are updated manually by the OverWatch team

C.

When events are recorded with Charlotte AI interactions

D.

When events are generated for a process that started before the sensor

Questions 33

CrowdStrike implements a specific framework within the Falcon console to help responders categorize detections based on the adversary’s ultimate goals and the technical means used to achieve them. This classification system, which maps activity to known industry standards, is known as the:

Options:
A.

MITRE-Based Falcon Detections Framework

B.

Falcon Adversary Attribution and Motivation Matrix

C.

Unified Behavioral Threat Hunting Schema

D.

CrowdStrike Intelligence Lifecycle Mapping

Questions 34

You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?

Options:
A.

Falcon X

B.

Investigate

C.

Discover

D.

Spotlight

Questions 35

When using ' User Search ' to investigate a potentially compromised account, which of the following is NOT a filter available in the User Search?

Options:
A.

Username

B.

Hostname

C.

Process ID

D.

Time Range

Questions 36

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Options:
A.

Identifies a detailed list of all process executions for the specified hashes

B.

Identifies hosts that loaded or executed the specified hashes

C.

Identifies users associated with the specified hashes

D.

Identifies detections related to the specified hashes

Questions 37

What is an advantage of using the IP Search tool?

Options:
A.

IP searches provide manufacture and timezone data that can not be accessed anywhere else

B.

IP searches allow for multiple comma separated IPv6 addresses as input

C.

IP searches offer shortcuts to launch response actions and network containment on target hosts

D.

IP searches provide host, process, and organizational unit data without the need to write a query

Questions 38

Which of the following sentences best describes the primary objective of ' Real-time Analysis ' within the Falcon platform?

Options:
A.

Analyzing historical logs from the past 90 days to find missed threats.

B.

Investigating incoming telemetry in real time or on a near real-time basis to catch active threats.

C.

Scanning every file on a hard drive once per week for dormant viruses.

D.

Manually updating the Falcon sensor on every machine in the fleet.

Questions 39

Which of the following tactic and technique combinations is sourced from MITRE ATT AND CK information?

Options:
A.

Falcon Intel via Intelligence Indicator - Domain

B.

Machine Learning via Cloud-Based ML

C.

Malware via PUP

D.

Credential Access via OS Credential Dumping

Questions 40

Which is TRUE regarding a file released from quarantine?

Options:
A.

No executions are allowed for 14 days after release

B.

It is allowed to execute on all hosts

C.

It is deleted

D.

It will not generate future machine learning detections on the associated host