
Free CCFR-201 Braindumps Download Updated on Oct 03, 2025 with 63 Questions
CrowdStrike CCFR-201 Exam Practice Test Questions
CrowdStrike CCFR-201 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 18
What action is used when you want to save a prevention hash for later use?
- A. No Action
- B. Always Block
- C. Never Block
- D. Always Allow
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Always Block action allows you to block a file from executing on any host in your organization based on its hash value2. This action can be used to prevent known malicious files from running on your endpoints2.
NEW QUESTION # 19
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
- A. The sensor will stop sending events from the process specified in the regex pattern
- B. The associated IOA will still generate a detection but the associated process would have been allowed to run
- C. The associated detection will be suppressed and the associated process would have been allowed to run
- D. The process specified is not sent to the Falcon Sandbox for analysis
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, IOA exclusions allow you to exclude files or directories from being detected or blocked by CrowdStrike's indicators of attack (IOAs), which are behavioral rules that identify malicious activities1. This can reduce false positives and improve performance1. When you configure and apply an IOA exclusion, the impact is that the associated detection will be suppressed and theassociated process would have been allowed to run1. This means that you will not see any alerts or events related to that IOA in the console1.
NEW QUESTION # 20
Where are quarantined files stored on Windows hosts?
- A. Windows\temp\Drivers\CrowdStrike\Quarantine
- B. Windows\Quarantine
- C. Windows\System32\
- D. Windows\System32\Drivers\CrowdStrike\Quarantine
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.
NEW QUESTION # 21
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
- A. Investigate
- B. Spotlight
- C. Discover
- D. Falcon X
Answer: A
Explanation:
Explanation
According to the [CrowdStrike website], the Investigate page is where you can search for and analyze various types of data collected by the Falcon platform, such as events, hosts, processes, hashes, domains, IPs, etc1. You can use various tools, such as Event Search, Host Search, Process Timeline, Hash Search, Bulk Domain Search, etc., to perform different types of searches and view the results in different ways1. If you want to search for any domain request information related to a notice from a third-party, you can use the Investigate page to do so1. For example, you can use the Bulk Domain Search tool to search for the malicious domain and see which hosts and processes communicated with it1. You can also use the Event Search tool to search for DNSRequest events that contain the malicious domain and see more details about the query and response1.
NEW QUESTION # 22
Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?
- A. Machine Learning via Cloud-Based ML
- B. Falcon Intel via Intelligence Indicator - Domain
- C. Credential Access via OS Credential Dumping
- D. Malware via PUP
Answer: C
Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. Credential Access via OS Credential Dumping is an example of a tactic and technique combination sourced from MITRE ATT&CK information, which describes how adversaries can obtain credentials from operating system memory or disk storage by using tools such as Mimikatz or ProcDump.
NEW QUESTION # 23
Which of the following is NOT a filter available on the Detections page?
- A. Triggering File
- B. Time
- C. Severity
- D. CrowdScore
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Detections page allows you to view and manage detections generated by the CrowdStrike Falcon platform2. You can use various filters to narrow down the detections based on criteria such as severity, CrowdScore, time, tactic, technique, etc2. However, there is no filter for triggering file, which is the file that caused the detection2.
NEW QUESTION # 24
From a detection, what is the fastest way to see children and sibling process information?
- A. Select the Event Search option. Then from the Event Actions, select Show Associated Event Data (From TargetProcessld_decimal)
- B. Select Full Detection Details from the detection
- C. Select the Process Timeline feature, enter the AID. Target Process ID, and Parent Process ID
- D. Right-click the process and select "Follow Process Chain"
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Full Detection Details tool allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1. The process tree view provides a graphical representation of the process hierarchy and activity1. You can see children and sibling processes information by expanding or collapsing nodes in the tree1.
NEW QUESTION # 25
In the Hash Search tool, which of the following is listed under Process Executions?
- A. File Signature
- B. Sensor Version
- C. Command Line
- D. Operating System
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that loaded or executed those hashes1. You can also see a count of detections and incidents related to those hashes1. Under Process Executions, you can see the process name and command line for each hash execution1.
NEW QUESTION # 26
How long are quarantined files stored on the host?
- A. 90 Days
- B. 30 Days
- C. Quarantined files are never deleted from the host
- D. 45 Days
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, quarantined files are never deleted from the host unless you manually delete them or release them from quarantine2. When you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization2. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud2.
NEW QUESTION # 27
What happens when a hash is allowlisted?
- A. The hash is submitted for approval to be allowed to execute once confirmed by Falcon specialists
- B. Execution is prevented, but detection alerts are suppressed
- C. Execution is allowed on all hosts, including all other Falcon customers
- D. Execution is allowed on all hosts that fall under the organization's CID
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the allowlist feature allows you to exclude files or directories from being scanned or blocked by CrowdStrike's machine learning engine or indicators of attack (IOAs)2. This can reduce false positives and improve performance2. When you allowlist a hash, you are allowing that file to execute on any host that belongs to your organization's CID (customer ID)2. This does not affect other Falcon customers or hosts outside your CID2.
NEW QUESTION # 28
Which statement is TRUE regarding the "Bulk Domains" search?
- A. It will show a list of computers and process that performed a lookup of any of the domains in your search
- B. The "Bulk Domains" search will show IP address and port information for any associated connectionsD.You should only pivot to the "Bulk Domains" search tool after completing an investigation
- C. The "Bulk Domains" search will allow you to blocklist your queried domains
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Bulk Domain Search tool allows you to search for one or more domains and view a summary of information from Falcon events that contain those domains2. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that performed a lookup of any of the domains in your search2. This can help you identify potential threats or vulnerabilities in your network2.
NEW QUESTION # 29
The function of Machine Learning Exclusions is to___________.
- A. Stop all Machine Learning Preventions but a detection will still be generated and files will still be uploaded to the CrowdStrike Cloud
- B. stop all detections for a specific pattern ID
- C. stop all sensor data collection for the matching path(s)
- D. stop all ML-based detections and preventions for the matching path(s) and/or stop files from being uploaded to the CrowdStrike Cloud
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, Machine Learning Exclusions allow you to exclude files or directories from being scanned by CrowdStrike's machine learning engine, which can reduce false positives and improveperformance2. You can also choose whether to upload the excluded files to the CrowdStrike Cloud or not2.
NEW QUESTION # 30
In the "Full Detection Details", which view will provide an exportable text listing of events like DNS requests.
Registry Operations, and Network Operations?
- A. View as Process Tree
- B. Thedata is unable to be exported
- C. View as Process Activity
- D. View as Process Timeline
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Full Detection Details tool allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1. The process activity view provides a rows-and-columns style view of the events, such as DNS requests, registry operations, network operations, etc1. You can also export this view to a CSV file for further analysis1.
NEW QUESTION # 31
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
- A. Identifies hosts that loaded or executed the specified hashes
- B. Identifies a detailed list of all process executions for the specified hashes
- C. Identifies users associated with the specified hashes
- D. Identifies detections related to the specified hashes
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Execution Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that loaded or executed those hashes1. You can also see a count of detections and incidents related to those hashes1.
NEW QUESTION # 32
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
- A. User logons after the detection
- B. Scheduled tasks registered prior to the detection
- C. Executions of schtasks.exe after the detection
- D. Pivot to a Hash search for taskeng.exe
Answer: B
Explanation:
Explanation
According to the [Microsoft website], taskeng.exe is a legitimate Windows process that is responsible for running scheduled tasks. However, some malware may use this process or create a fake one to execute malicious code. Therefore, if you notice taskeng.exe involved in a detection, you should investigate whether there are any scheduled tasks registered prior to the detection that may have triggered or injected into taskeng.exe. You can use tools such as schtasks.exe or Task Scheduler to view or manage scheduled tasks.
NEW QUESTION # 33
......
Updated Verified CCFR-201 dumps Q&As - Pass Guarantee or Full Refund: https://examtorrent.testkingpdf.com/CCFR-201-testking-pdf-torrent.html

