CrowdStrike CCFR-201 - CrowdStrike Certified Falcon Responder Exam
Page: 3 / 12
Total 60 questions
Question #11 (Topic: Exam A)
What action is used when you want to save a prevention hash for later use?
A. Always Block
B. Never Block
C. Always Allow
D. No Action
Answer: A
Question #12 (Topic: Exam A)
You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?
A. IP Addresses
B. Remote or Network Logon Activity
C. Remote Access Graph
D. Hash Executions
Answer: A
Question #13 (Topic: Exam A)
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenInfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
A. ParentProcessId_decimal and aid
B. ResponsibleProcessId_decimal and aid
C. ContextProcessId_decimal and aid
D. TargetProcessId_decimal and aid
Answer: B
Question #14 (Topic: Exam A)
How long are quarantined files stored in the CrowdStrike Cloud?
A. 45 Days
B. 90 Days
C. 30 Days
D. Quarantined files are not deleted
Answer: B
Question #15 (Topic: Exam A)
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
A. Falcon X
B. Investigate
C. Discover
D. Spotlight
Answer: B