[Mar-2024] CCFR-201 Exam Dumps Pass with Updated 2024 CrowdStrike Certified Falcon Responder [Q27-Q46]

Share

[Mar-2024] CCFR-201 Exam Dumps Pass with Updated 2024 CrowdStrike Certified Falcon Responder

Free CCFR-201 Exam Dumps to Pass Exam Easily

NEW QUESTION # 27
How are processes on the same plane ordered (bottom 'VMTOOLSD.EXE' to top CMD.EXE')?

  • A. Process ID (Ascending, highest on top)
  • B. Time started (Descending, most recent on bottom)
  • C. Time started (Ascending, most recent on top)
  • D. Process ID (Descending, highest on bottom)

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the process tree view provides a visualization of program ancestry, which shows the parent-child and sibling relationships among the processes1. You can also see the event types and timestamps for each process1. The processes on the same plane are ordered by time started in descending order, meaning that the most recent process is at the bottom and the oldest process is at the top1. For example, in the image you sent me, CMD.EXE is the oldest process and VMTOOLSD.EXE is the most recent process on that plane1.


NEW QUESTION # 28
The Process Activity View provides a rows-and-columns style view of the events generated in a detection.
Why might this be helpful?

  • A. The Process Activity View only creates a summary of Dynamic Link Libraries (DLLs) loaded by a process
  • B. The Process Activity View will show the Detection time of the earliest recorded activity which might indicate first affected machine
  • C. The Process Activity View creates a count of event types only, which can be useful when scoping the event
  • D. The Process Activity View creates a consolidated view of all detection events for that process that can be exported for further analysis

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Activity View allows you to view all events generated by a process involved in a detection in a rows-and-columns style view1. This can be helpful because it creates a consolidated view of all detection events for that process that can be exported for further analysis1. You can also sort, filter, and pivot on the events by various fields, such as event type, timestamp, file name, registry key, network destination, etc1.


NEW QUESTION # 29
From a detection, what is the fastest way to see children and sibling process information?

  • A. Select the Event Search option. Then from the Event Actions, select Show Associated Event Data (From TargetProcessld_decimal)
  • B. Right-click the process and select "Follow Process Chain"
  • C. Select Full Detection Details from the detection
  • D. Select the Process Timeline feature, enter the AID. Target Process ID, and Parent Process ID

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Full Detection Details tool allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1. The process tree view provides a graphical representation of the process hierarchy and activity1. You can see children and sibling processes information by expanding or collapsing nodes in the tree1.


NEW QUESTION # 30
What happens when a quarantined file is released?

  • A. It is allowed to execute on the host
  • B. It is moved into theC:\CrowdStrike\Quarantine\Releasedfolder on the host
  • C. It is allowed to execute on all hosts
  • D. It is deleted

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization1. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud1.


NEW QUESTION # 31
Which of the following is returned from the IP Search tool?

  • A. Threat Graph Data for the given IP from Falcon sensors
  • B. Unmanaged host data from system ARP tables for the given IPD.IP Detection Summary information for detection events containing the given IP
  • C. IP Summary information from Falcon events containing the given IP

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the IP Search tool allows you to search for an IP address and view a summary of information from Falcon events that contain that IP address1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that communicated with that IP address1.


NEW QUESTION # 32
Which option indicates a hash is allowlisted?

  • A. Always Block
  • B. Ignore
  • C. Allow
  • D. No Action

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the allowlist feature allows you to exclude files or directories from being scanned or blocked by CrowdStrike's machine learning engine or indicators of attack (IOAs)2. This can reduce false positives and improve performance2. When you allowlist a hash, you are allowing that file to execute on any host that belongs to your organization's CID (customer ID)2. The option to indicate that a hash is allowlisted is "Allow"2.


NEW QUESTION # 33
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in
.CSV format?

  • A. From the Detections Dashboard, you right-click the event type you wish to export and choose CSV.JSON or XML
  • B. You can't export detailed event data from a detection, you have to use the Process Timeline or an Event Search
  • C. In Full Detection Details, you choose the "View Process Activity" option and then export from that view
  • D. In Full Detection Details, you expand the nodes of the process tree you wish to expand and then click the "Export Process Events" button

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, there are three ways to export process event data from a detection in .CSV format1:
You can use the Process Timeline tool and click on "Export CSV" button at the top right corner1.
You can use the Event Search tool and select one or more events and click on "Export CSV" button at the top right corner1.
You can use the Full Detection Details tool and choose the "View Process Activity" option from any process node in the process tree view1. This will show you all events generated bythat process in a rows-and-columns style view1. You can then click on "Export CSV" button at the top right corner1.


NEW QUESTION # 34
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?

  • A. Show a Process Timeline for the responsible process
  • B. Show a +/- 10-minute window of events
  • C. Draw Process Explorer
  • D. Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Event Search tool allows you to search for events based on various criteria, such as event type, timestamp, hostname, IP address, etc1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. However, there is no option to draw a process explorer, which is a graphical representation of the process hierarchy and activity1.


NEW QUESTION # 35
What action is used when you want to save a prevention hash for later use?

  • A. Never Block
  • B. Always Block
  • C. Always Allow
  • D. No Action

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Always Block action allows you to block a file from executing on any host in your organization based on its hash value2. This action can be used to prevent known malicious files from running on your endpoints2.


NEW QUESTION # 36
How does a DNSRequest event link to its responsible process?

  • A. Via its TargetProcessld_decimal field
  • B. Via its ContextProcessld_decimal field
  • C. Via both its ContextProcessld__decimal and ParentProcessld_decimal fields
  • D. Via its ParentProcessld_decimal field

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2. The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2. The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2. You can use this field to trace the process lineage and identify malicious or suspicious activities2.


NEW QUESTION # 37
The function of Machine Learning Exclusions is to___________.

  • A. Stop all Machine Learning Preventions but a detection will still be generated and files will still be uploaded to the CrowdStrike Cloud
  • B. stop all detections for a specific pattern ID
  • C. stop all sensor data collection for the matching path(s)
  • D. stop all ML-based detections and preventions for the matching path(s) and/or stop files from being uploaded to the CrowdStrike Cloud

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, Machine Learning Exclusions allow you to exclude files or directories from being scanned by CrowdStrike's machine learning engine, which can reduce false positives and improveperformance2. You can also choose whether to upload the excluded files to the CrowdStrike Cloud or not2.


NEW QUESTION # 38
What information does the MITRE ATT&CKFramework provide?

  • A. It provides a step-by-step cyber incident response strategy
  • B. It is a system that attributes an attack techniques to a specific threat actor
  • C. It provides best practices for different cybersecurity domains, such as Identify and Access Management
  • D. It provides the phases of an adversary's lifecycle, the platforms they are known to attack, and the specific methods they use

Answer: D

Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. The knowledge base also covers different platforms that adversaries target, such as Windows, Linux, Mac, Android, iOS, etc., and different phases of an adversary's lifecycle, such as reconnaissance, resource development, execution, command and control, etc.


NEW QUESTION # 39
Where are quarantined files stored on Windows hosts?

  • A. Windows\System32\
  • B. Windows\temp\Drivers\CrowdStrike\Quarantine
  • C. Windows\Quarantine
  • D. Windows\System32\Drivers\CrowdStrike\Quarantine

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.


NEW QUESTION # 40
How long are quarantined files stored in the CrowdStrike Cloud?

  • A. Quarantined files are not deleted
  • B. 90 Days
  • C. 45 Days
  • D. Days

Answer: B

Explanation:
Explanation
According to the [CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide], when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed. The file is also encrypted and renamed with a random string of characters. A copy of the file is also uploaded to the CrowdStrike Cloud for further analysis. Quarantined files are stored in the CrowdStrike Cloud for 90 days before they are deleted.


NEW QUESTION # 41
Sensor Visibility Exclusion patterns are written in which syntax?

  • A. SPL(Splunk)
  • B. Glob Syntax
  • C. Kleene Star Syntax
  • D. RegEx

Answer: B

Explanation:
Explanation
According to the [CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide], Sensor Visibility Exclusions allow you to exclude files or directories from being monitored by the sensor. This can reduce the amount of data sent to the CrowdStrike Cloud and improve performance. Sensor Visibility Exclusion patterns are written in Glob Syntax, which is a simple pattern matching syntax that supports wildcards, such as *, ?, and . For example, you can use *.exe to exclude all files with .exe extension.


NEW QUESTION # 42
Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?

  • A. adversary is trying to keep access through persistence using application skimming
  • B. An adversary is trying to keep access through persistence using browser extensions
  • C. An adversary is trying to keep access through persistence using external remote services
  • D. An adversary is trying to keep access through persistence by creating an account

Answer: D

Explanation:
Explanation
According to the [CrowdStrike website], the MITRE-Based Falcon Detections Framework is a way of categorizing and describing detections based on the MITRE ATT&CK knowledge base ofadversary behaviors and techniques. The framework uses three levels of granularity: category, tactic, and technique. The category is the highest level and represents the main objective of an adversary, such as initial access, execution, credential access, etc. The tactic is the second level and represents the sub-objective of an adversary within a category, such as persistence, privilege escalation, defense evasion, etc. The technique is the lowest level and represents the specific way an adversary can achieve a tactic, such as create account, modify registry, obfuscated files or information, etc. Therefore, the correct way to interpret Keep Access > Persistence > Create Account is that an adversary is trying to keep access through persistence by creating an account.


NEW QUESTION # 43
What does pivoting to an Event Search from a detection do?

  • A. It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection
  • B. It gives you the ability to search for similar events on other endpoints quickly
  • C. It takes you to the raw Insight event data and provides you with a number of Event Actions
  • D. It takes you to a Process Timeline for that detection so you can see all related events

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, pivoting to an Event Search from a detection takes you to the raw Insight event data and provides you with a number of Event Actions1. Insight events are low-level events that are generated by the sensor for various activities, such as process executions, file writes, registry modifications, network connections, etc1. You can view these events in a table format and use various filters and fields to narrow down the results1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. These actions can help you investigate and analyze events more efficiently and effectively1.


NEW QUESTION # 44
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

  • A. Identifies users associated with the specified hashes
  • B. Identifies a detailed list of all process executions for the specified hashes
  • C. Identifies detections related to the specified hashes
  • D. Identifies hosts that loaded or executed the specified hashes

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Execution Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that loaded or executed those hashes1. You can also see a count of detections and incidents related to those hashes1.


NEW QUESTION # 45
You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?

  • A. UTCtime
  • B. PID
  • C. Process ID or Parent Process ID
  • D. ProcessTimeline Link

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc1. The tool requires two parameters: aid (agent ID) and TargetProcessId_decimal (the decimal value of the process ID)1. You can jump to a Process Timeline from many views, such as Hash Search, Host Timeline, Event Search, etc., by clicking on either the Process ID or Parent Process ID fields in those views1. This will automatically populate the aid and TargetProcessId_decimal parameters for the Process Timeline tool1.


NEW QUESTION # 46
......

CCFR-201 Exam Dumps, CCFR-201 Practice Test Questions: https://www.dumpsquestion.com/CCFR-201-exam-dumps-collection.html

Free CCFR-201 Study Guides Exam Questions and Answer: https://drive.google.com/open?id=15IqF5xhnbiyLktC3PXSo5dLQgfOlxcT4