
Top CrowdStrike CCFR-201 Courses Online - Updated [Oct-2023]
CCFR-201 Practice Dumps - Verified By ValidTorrent Updated 63 Questions
NEW QUESTION # 18
Which is TRUE regarding a file released from quarantine?
- A. It will not generate future machine learning detections on the associated host
- B. It is deleted
- C. No executions are allowed for 14 days after release
- D. It is allowed to execute on all hosts
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization2. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud2.
NEW QUESTION # 19
What action is used when you want to save a prevention hash for later use?
- A. Always Block
- B. Always Allow
- C. No Action
- D. Never Block
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Always Block action allows you to block a file from executing on any host in your organization based on its hash value2. This action can be used to prevent known malicious files from running on your endpoints2.
NEW QUESTION # 20
Which Executive Summary dashboard item indicates sensors running with unsupported versions?
- A. Active Sensors
- B. Detections by Severity
- C. Inactive Sensors
- D. Sensors in RFM
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Executive Summary dashboard provides an overview of your sensor health and activity1. It includes various items, such as Active Sensors, Inactive Sensors, Detections by Severity, etc1. The item that indicates sensors running with unsupported versions is Sensors in RFM (Reduced Functionality Mode)1. RFM is a state where a sensor has limited functionality due to various reasons, such as license expiration, network issues, tampering attempts, or unsupported versions1. You can see the number and percentage of sensors in RFM and the reasons why they are in RFM1.
NEW QUESTION # 21
From a detection, what is the fastest way to see children and sibling process information?
- A. Right-click the process and select "Follow Process Chain"
- B. Select the Event Search option. Then from the Event Actions, select Show Associated Event Data (From TargetProcessld_decimal)
- C. Select Full Detection Details from the detection
- D. Select the Process Timeline feature, enter the AID. Target Process ID, and Parent Process ID
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Full Detection Details tool allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1. The process tree view provides a graphical representation of the process hierarchy and activity1. You can see children and sibling processes information by expanding or collapsing nodes in the tree1.
NEW QUESTION # 22
How long does detection data remain in the CrowdStrike Cloud before purging begins?
- A. 90 Days
- B. 14 Days
- C. 30 Days
- D. 45 Days
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, detection data is stored in the CrowdStrike Cloud for 90 days before purging begins2. This means that you can access and view detections from the past 90 days using the Falcon platform or API2. If you want to retain detection data for longer than 90 days, you can use FDR to replicate it to your own storage system2.
NEW QUESTION # 23
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Falcon platform will show a maximum of 1000 detections per day for a single AID1. This is a limitimposed by the Falcon API, which is used to retrieve the detections from the CrowdStrike Cloud1. If there are more than 1000 detections per day for a single AID, only the first 1000 will be shown1.
NEW QUESTION # 24
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence.
Which answer best defines Local Prevalence?
- A. Local Prevalence is the Virus Total score for the hash of the triggering file
- B. Local Prevalence tells you how common the hash of the triggering file is within your environment (CID)
- C. Local prevalence is the frequency with which the hash of the triggering file is seen across all CrowdStrike customer environments
- D. Local prevalence is the frequency with which the hash of the triggering file is seen across the entire Internet
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, Global Prevalence and Local Prevalence are two fields that provide information about how common or rare a file is based on its hash value2. Global Prevalence tells you how frequently the hash of the triggering file is seen across all CrowdStrike customer environments2. Local Prevalence tells you how frequently the hash of the triggering file is seen within your environment (CID)2. These fields can help you assess the risk and impact of a detection2.
NEW QUESTION # 25
When reviewing a Host Timeline, which of the following filters is available?
- A. Severity
- B. Event Types
- C. User Name
- D. Detection ID
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Host Timeline tool allows you to view all events recorded by the sensor for a given host in a chronological order1. The events include process executions, file writes, registry modifications, network connections, user logins, etc1. You can use various filters to narrow down the events based on criteria such as event type, timestamp range, file name, registry key, network destination, etc1. However, there is no filter for severity, user name, or detection ID, as these are not attributes of the events1.
NEW QUESTION # 26
How does a DNSRequest event link to its responsible process?
- A. Via both its ContextProcessld__decimal and ParentProcessld_decimal fields
- B. Via its ParentProcessld_decimal field
- C. Via its ContextProcessld_decimal field
- D. Via its TargetProcessld_decimal field
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2. The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2. The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2. You can use this field to trace the process lineage and identify malicious or suspicious activities2.
NEW QUESTION # 27
Where are quarantined files stored on Windows hosts?
- A. Windows\System32\Drivers\CrowdStrike\Quarantine
- B. Windows\System32\
- C. Windows\temp\Drivers\CrowdStrike\Quarantine
- D. Windows\Quarantine
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.
NEW QUESTION # 28
Which of the following is NOT a filter available on the Detections page?
- A. Severity
- B. CrowdScore
- C. Triggering File
- D. Time
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Detections page allows you to view and manage detections generated by the CrowdStrike Falcon platform2. You can use various filters to narrow down the detections based on criteria such as severity, CrowdScore, time, tactic, technique, etc2. However, there is no filter for triggering file, which is the file that caused the detection2.
NEW QUESTION # 29
What information does the MITRE ATT&CKFramework provide?
- A. It is a system that attributes an attack techniques to a specific threat actor
- B. It provides best practices for different cybersecurity domains, such as Identify and Access Management
- C. It provides a step-by-step cyber incident response strategy
- D. It provides the phases of an adversary's lifecycle, the platforms they are known to attack, and the specific methods they use
Answer: D
Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. The knowledge base also covers different platforms that adversaries target, such as Windows, Linux, Mac, Android, iOS, etc., and different phases of an adversary's lifecycle, such as reconnaissance, resource development, execution, command and control, etc.
NEW QUESTION # 30
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
- A. It contains the TargetProcessld_decimal of the parent process
- B. It contains an internal value not useful for an investigation
- C. It contains the TargetProcessld_decimal value of the child process
- D. It contains the Sensorld_decimal value for related events
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ParentProcessld_decimal field contains the decimal value of the process ID of the parent process that spawned or injected into the target process1. This field can be used to trace the process lineage and identify malicious or suspicious activities1.
NEW QUESTION # 31
You receive an email from a third-party vendor that one of their services is compromised,thevendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?
- A. Hash Executions
- B. IP Addresses
- C. Remote Access Graph
- D. Remote or Network Logon Activity
Answer: B
Explanation:
Explanation
According to the [CrowdStrike website], the Discover page is where you can search for and analyze various types of indicators of compromise (IOCs), such as hashes, IP addresses, or domains that are associated with malicious activities. You can use various tools, such as Hash Executions, IP Addresses, Remote or Network Logon Activity, etc., to perform different types of searches and view the results in different ways. If you want to search for any activity related to an IP address that was compromised by a third-party vendor, you can use the IP Addresses tool to do so. You can input the IP address and see a summary of information from Falcon events that contain that IP address, such as hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that communicated with that IP address.
NEW QUESTION # 32
Which statement is TRUE regarding the "Bulk Domains" search?
- A. The "Bulk Domains" search will show IP address and port information for any associated connectionsD.You should only pivot to the "Bulk Domains" search tool after completing an investigation
- B. The "Bulk Domains" search will allow you to blocklist your queried domains
- C. It will show a list of computers and process that performed a lookup of any of the domains in your search
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Bulk Domain Search tool allows you to search for one or more domains and view a summary of information from Falcon events that contain those domains2. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that performed a lookup of any of the domains in your search2. This can help you identify potential threats or vulnerabilities in your network2.
NEW QUESTION # 33
......
New (2023) CrowdStrike CCFR-201 Exam Dumps: https://www.validtorrent.com/CCFR-201-valid-exam-torrent.html
Updated CCFR-201 Exam Dumps - PDF Questions and Testing Engine: https://drive.google.com/open?id=1LVh3YNrcye6BZOcsqDyNSzYTrykyKbkq