Get New 2023 Valid Practice To your CCFR-201 Exam (Updated 63 Questions) [Q31-Q50]

Share

Get New 2023 Valid Practice To your CCFR-201 Exam (Updated 63 Questions)

CrowdStrike CCFR CCFR-201 Exam Practice Test Questions Dumps Bundle!

NEW QUESTION # 31
How are processes on the same plane ordered (bottom 'VMTOOLSD.EXE' to top CMD.EXE')?

  • A. Time started (Descending, most recent on bottom)
  • B. Process ID (Descending, highest on bottom)
  • C. Process ID (Ascending, highest on top)
  • D. Time started (Ascending, most recent on top)

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the process tree view provides a visualization of program ancestry, which shows the parent-child and sibling relationships among the processes1. You can also see the event types and timestamps for each process1. The processes on the same plane are ordered by time started in descending order, meaning that the most recent process is at the bottom and the oldest process is at the top1. For example, in the image you sent me, CMD.EXE is the oldest process and VMTOOLSD.EXE is the most recent process on that plane1.


NEW QUESTION # 32
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?

  • A. aid and ParentProcessld_decimal
  • B. SHA256 and ParentProcessld_decimal
  • C. SHA256 and TargetProcessld_decimal
  • D. aid and TargetProcessld_decimal

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline search requires two parameters: aid (agent ID) and TargetProcessId_decimal (the decimal value of the process ID). These fields can be obtained from the ProcessRollup2 event, which contains information about processes that have executed on a host1.


NEW QUESTION # 33
What information does the MITRE ATT&CKFramework provide?

  • A. It provides best practices for different cybersecurity domains, such as Identify and Access Management
  • B. It provides a step-by-step cyber incident response strategy
  • C. It provides the phases of an adversary's lifecycle, the platforms they are known to attack, and the specific methods they use
  • D. It is a system that attributes an attack techniques to a specific threat actor

Answer: C

Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. The knowledge base also covers different platforms that adversaries target, such as Windows, Linux, Mac, Android, iOS, etc., and different phases of an adversary's lifecycle, such as reconnaissance, resource development, execution, command and control, etc.


NEW QUESTION # 34
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?

  • A. A managed neighbor has an installed and provisioned sensor
  • B. An unmanaged neighbor is in a segmented area of the network
  • C. A managed neighbor is currently network contained and an unmanaged neighbor is uncontained
  • D. A managed sensor has an active prevention policy

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, you can use the Hosts page in the Investigate tool to view information about your endpoints, such as hostname, IP address, OS, sensor version, etc2. You can also see a list of managed and unmanaged neighbors for each endpoint, which are other devices that have communicated with that endpoint over the network2. A managed neighbor is a device that has an installed and provisioned sensor that reports to the CrowdStrike Cloud2. An unmanaged neighbor is a device that does not have an installed or provisioned sensor2.


NEW QUESTION # 35
Which Executive Summary dashboard item indicates sensors running with unsupported versions?

  • A. Detections by Severity
  • B. Sensors in RFM
  • C. Active Sensors
  • D. Inactive Sensors

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Executive Summary dashboard provides an overview of your sensor health and activity1. It includes various items, such as Active Sensors, Inactive Sensors, Detections by Severity, etc1. The item that indicates sensors running with unsupported versions is Sensors in RFM (Reduced Functionality Mode)1. RFM is a state where a sensor has limited functionality due to various reasons, such as license expiration, network issues, tampering attempts, or unsupported versions1. You can see the number and percentage of sensors in RFM and the reasons why they are in RFM1.


NEW QUESTION # 36
What happens when a hash is allowlisted?

  • A. Execution is prevented, but detection alerts are suppressed
  • B. The hash is submitted for approval to be allowed to execute once confirmed by Falcon specialists
  • C. Execution is allowed on all hosts that fall under the organization's CID
  • D. Execution is allowed on all hosts, including all other Falcon customers

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the allowlist feature allows you to exclude files or directories from being scanned or blocked by CrowdStrike's machine learning engine or indicators of attack (IOAs)2. This can reduce false positives and improve performance2. When you allowlist a hash, you are allowing that file to execute on any host that belongs to your organization's CID (customer ID)2. This does not affect other Falcon customers or hosts outside your CID2.


NEW QUESTION # 37
What action is used when you want to save a prevention hash for later use?

  • A. Always Block
  • B. Always Allow
  • C. No Action
  • D. Never Block

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Always Block action allows you to block a file from executing on any host in your organization based on its hash value2. This action can be used to prevent known malicious files from running on your endpoints2.


NEW QUESTION # 38
What happens when you create a Sensor Visibility Exclusion for a trusted file path?

  • A. It excludes host information from Detections and Incidents generated within that file path location
  • B. It excludes sensor monitoring and event collection for the trusted file path
  • C. It disables detection generation from that path, however the sensor can still perform prevention actions
  • D. It prevents file uploads to the CrowdStrike cloud from that file path

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, Sensor Visibility Exclusions allow you to exclude certain files or directories from being monitored by the CrowdStrike sensor, which can reduce noise and improve performance2. This means that no events will be collected or sent to the CrowdStrike Cloud for those files or directories2.


NEW QUESTION # 39
You receive an email from a third-party vendor that one of their services is compromised,thevendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?

  • A. Remote Access Graph
  • B. Remote or Network Logon Activity
  • C. IP Addresses
  • D. Hash Executions

Answer: C

Explanation:
Explanation
According to the [CrowdStrike website], the Discover page is where you can search for and analyze various types of indicators of compromise (IOCs), such as hashes, IP addresses, or domains that are associated with malicious activities. You can use various tools, such as Hash Executions, IP Addresses, Remote or Network Logon Activity, etc., to perform different types of searches and view the results in different ways. If you want to search for any activity related to an IP address that was compromised by a third-party vendor, you can use the IP Addresses tool to do so. You can input the IP address and see a summary of information from Falcon events that contain that IP address, such as hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that communicated with that IP address.


NEW QUESTION # 40
Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?

  • A. An adversary is trying to keep access through persistence by creating an account
  • B. An adversary is trying to keep access through persistence using browser extensions
  • C. adversary is trying to keep access through persistence using application skimming
  • D. An adversary is trying to keep access through persistence using external remote services

Answer: A

Explanation:
Explanation
According to the [CrowdStrike website], the MITRE-Based Falcon Detections Framework is a way of categorizing and describing detections based on the MITRE ATT&CK knowledge base ofadversary behaviors and techniques. The framework uses three levels of granularity: category, tactic, and technique. The category is the highest level and represents the main objective of an adversary, such as initial access, execution, credential access, etc. The tactic is the second level and represents the sub-objective of an adversary within a category, such as persistence, privilege escalation, defense evasion, etc. The technique is the lowest level and represents the specific way an adversary can achieve a tactic, such as create account, modify registry, obfuscated files or information, etc. Therefore, the correct way to interpret Keep Access > Persistence > Create Account is that an adversary is trying to keep access through persistence by creating an account.


NEW QUESTION # 41
Where are quarantined files stored on Windows hosts?

  • A. Windows\System32\
  • B. Windows\System32\Drivers\CrowdStrike\Quarantine
  • C. Windows\temp\Drivers\CrowdStrike\Quarantine
  • D. Windows\Quarantine

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.


NEW QUESTION # 42
Which of the following is returned from the IP Search tool?

  • A. Threat Graph Data for the given IP from Falcon sensors
  • B. IP Summary information from Falcon events containing the given IP
  • C. Unmanaged host data from system ARP tables for the given IPD.IP Detection Summary information for detection events containing the given IP

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the IP Search tool allows you to search for an IP address and view a summary of information from Falcon events that contain that IP address1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that communicated with that IP address1.


NEW QUESTION # 43
How long does detection data remain in the CrowdStrike Cloud before purging begins?

  • A. 45 Days
  • B. 14 Days
  • C. 30 Days
  • D. 90 Days

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, detection data is stored in the CrowdStrike Cloud for 90 days before purging begins2. This means that you can access and view detections from the past 90 days using the Falcon platform or API2. If you want to retain detection data for longer than 90 days, you can use FDR to replicate it to your own storage system2.


NEW QUESTION # 44
When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?

  • A. It contains the TargetProcessld_decimal value for other related events
  • B. It contains the ContextProcessld_decimal value for the parent process that made the DNS request
  • C. It contains an internal value not useful for an investigation
  • D. It contains the TargetProcessld_decimal value for the process that made the DNS request

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ContextProcessld_decimal field contains the decimal value of the process ID of the process that generated the event1. This field can be used to trace the process lineage and identify malicious or suspicious activities1. For a DNS request event, this field indicates which process made the DNS request1.


NEW QUESTION # 45
How does a DNSRequest event link to its responsible process?

  • A. Via both its ContextProcessld__decimal and ParentProcessld_decimal fields
  • B. Via its ContextProcessld_decimal field
  • C. Via its TargetProcessld_decimal field
  • D. Via its ParentProcessld_decimal field

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2. The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2. The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2. You can use this field to trace the process lineage and identify malicious or suspicious activities2.


NEW QUESTION # 46
What does pivoting to an Event Search from a detection do?

  • A. It takes you to the raw Insight event data and provides you with a number of Event Actions
  • B. It takes you to a Process Timeline for that detection so you can see all related events
  • C. It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection
  • D. It gives you the ability to search for similar events on other endpoints quickly

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, pivoting to an Event Search from a detection takes you to the raw Insight event data and provides you with a number of Event Actions1. Insight events are low-level events that are generated by the sensor for various activities, such as process executions, file writes, registry modifications, network connections, etc1. You can view these events in a table format and use various filters and fields to narrow down the results1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. These actions can help you investigate and analyze events more efficiently and effectively1.


NEW QUESTION # 47
What is an advantage of using a Process Timeline?

  • A. Suspicious processes are color-coded based on their frequency and legitimacy over time
  • B. Process related events can be filtered to display specific event types
  • C. A visual representation of Parent-Child and Sibling process relationships is provided
  • D. Processes responsible for spikes in CPU performance are displayed overtime

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc2. You can also filter the events by various criteria, such as event type, timestamp range, file name, registry key, network destination, etc2. This is an advantage of using the Process Timeline tool because it allows you to focus on specific events that are relevant to your investigation2.


NEW QUESTION # 48
Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?

  • A. Credential Access via OS Credential Dumping
  • B. Malware via PUP
  • C. Machine Learning via Cloud-Based ML
  • D. Falcon Intel via Intelligence Indicator - Domain

Answer: A

Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. Credential Access via OS Credential Dumping is an example of a tactic and technique combination sourced from MITRE ATT&CK information, which describes how adversaries can obtain credentials from operating system memory or disk storage by using tools such as Mimikatz or ProcDump.


NEW QUESTION # 49
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence.
Which answer best defines Local Prevalence?

  • A. Local Prevalence tells you how common the hash of the triggering file is within your environment (CID)
  • B. Local prevalence is the frequency with which the hash of the triggering file is seen across the entire Internet
  • C. Local prevalence is the frequency with which the hash of the triggering file is seen across all CrowdStrike customer environments
  • D. Local Prevalence is the Virus Total score for the hash of the triggering file

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, Global Prevalence and Local Prevalence are two fields that provide information about how common or rare a file is based on its hash value2. Global Prevalence tells you how frequently the hash of the triggering file is seen across all CrowdStrike customer environments2. Local Prevalence tells you how frequently the hash of the triggering file is seen within your environment (CID)2. These fields can help you assess the risk and impact of a detection2.


NEW QUESTION # 50
......

Fully Updated Dumps PDF - Latest CCFR-201 Exam Questions and Answers: https://www.lead2passed.com/CrowdStrike/CCFR-201-practice-exam-dumps.html