CCFR-201B Exam Questions
70 real CCFR-201B exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Falcon Platform Navigation and Search
What are Event Actions?
Event Actionsevent pivotingFalcon consolesearch automation - Question #2Prevention and Detection Management
Where are quarantined files stored on Windows hosts?
quarantinefile storageWindows hostCrowdStrike sensor - Question #3Falcon Platform Administration
How long does detection data remain in the CrowdStrike Cloud before purging begins?
data retentiondetection dataCrowdStrike Clouddata lifecycle - Question #4Prevention and Detection Management
Which is TRUE regarding a file released from quarantine?
quarantine releasemachine learningfile executionhost policy - Question #5Detection Investigation and Triage
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
Detections pagefilteringanalyst assignmentdetection status - Question #6Threat Intelligence and Investigation Tools
The Bulk Domain Search tool contains Domain information along with which of the following?
Bulk Domain Searchdomain informationprocess informationthreat intelligence - Question #7Detection Investigation and Triage
The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?
Process Activity Viewdetection eventsevent analysisprocess investigation - Question #8Falcon Platform Administration
Which Executive Summary dashboard item indicates sensors running with unsupported versions?
Executive Summary dashboardRFMsensor versionssensor health - Question #9Prevention and Detection Management
What do IOA exclusions help you achieve?
IOA exclusionsfalse positivesbehavioral detectionsprevention policy - Question #10Event Data Analysis and Investigation
When examining a raw DNS request event, you see a field called ContextProcessId_decimal. What is the purpose of that field?
DNS request eventContextProcessId_decimalraw event dataprocess identification - Question #11Prevention and Detection Management
The function of Machine Learning Exclusions is to _____________.
Machine Learning ExclusionsML preventionpath exclusionsdetection suppression - Question #12Threat Intelligence and Investigation Tools
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
Hash Execution SearchSHA256process executionshost identification - Question #13Threat Intelligence and Investigation Tools
In the Hash Search tool, which of the following is listed under Process Executions?
Hash SearchProcess Executionscommand lineevent fields - Question #14Falcon Platform Navigation and Search
What is the difference between a Host Search and a Host Timeline?
Host SearchHost Timelineevent organizationinvestigation views - Question #15Falcon Platform Administration
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
managed neighborsunmanaged neighborssensor provisioningnetwork discovery - Question #16Threat Intelligence and Investigation Tools
What is an advantage of using the IP Search tool?
IP Searchhost datainvestigation shortcutsnetwork investigation - Question #17Detection Investigation and Triage
What happens when you open the full detection details?
detection detailsprocess explorerprocess relationshipsdetection investigation - Question #18Event Data Analysis and Investigation
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so y...
ProcessRollup2Process TimelineaidTargetProcessId_decimal - Question #19Event Data Analysis and Investigation
Which of the following is NOT a valid event type?
event typesProcessRollup2DnsRequestEndofProcess - Question #20Event Data Analysis and Investigation
When examining raw event data, what is the purpose of the field called ParentProcessId_decimal?
ParentProcessId_decimalraw event dataparent processprocess relationships - Question #21Investigate Tools and Features
Which of the following is returned from the IP Search tool?
IP SearchInvestigate toolFalcon eventsIP Summary - Question #22Process Analysis and Investigation
What types of events are returned by a Process Timeline?
Process Timelinecloudable eventsevent typessensor data - Question #23Event Search and Analysis
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
Event SearchEvent ActionsProcess Explorerprocess timeline - Question #24Detection Investigation
From a detection, what is the fastest way to see children and sibling process information?
Full Detection Detailsprocess treesibling processesdetection navigation - Question #25Endpoint Visibility and Investigation
A list of managed and unmanaged neighbors for an endpoint can be found:
Hosts pageInvestigate toolnetwork neighborsunmanaged hosts - Question #26Sensor Configuration and Exclusions
What happens when you create a Sensor Visibility Exclusion for a trusted file path?
Sensor Visibility Exclusionevent collectiontrusted file pathsensor monitoring - Question #27Detection Investigation
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in .CSV format?
Full Detection Detailsexport CSVView Process Activityprocess event data - Question #28Platform Configuration and Limits
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
detection limitsAIDdetections per dayFalcon platform - Question #29Detection Analysis and Triage
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?
Local PrevalenceGlobal Prevalencehash reputationfile frequency - Question #30Detection Triage and Investigation
When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?
Global PrevalenceVirusTotalinvestigation workflowunknown executable - Question #31Threat Intelligence and MITRE ATT&CK
Which of the following is an example of a MITRE ATT&CK tactic?
MITRE ATT&CKtacticsDefense Evasionthreat framework - Question #32IOC Management and Prevention
What happens when a hash is set to Always Block through IOC Management?
IOC Managementhash blockinghost groupsAlways Block - Question #33Detection Management and Navigation
Which of the following is NOT a filter available on the Detections page?
Detections pagefiltersCrowdScoredetection management - Question #34Threat Hunting and Investigation
You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
Process TimelinenavigationProcess IDHash Search pivot - Question #35Prevention and Quarantine Management
How long are quarantined files stored on the host?
quarantinefile storage durationendpoint protection30 days - Question #36Threat Hunting and Investigation
Which statement is TRUE regarding the "Bulk Domains" search?
Bulk Domainsdomain investigationDNS lookupthreat hunting - Question #37Process Analysis and Investigation
How are processes on the same plane ordered (bottom 'VMTOOLSD.EXE' to top 'CMD.EXE')?
Process Explorerprocess orderingtime startedvisualization - Question #38Event Search and Analysis
What does pivoting to an Event Search from a detection do?
Event Searchdetection pivotraw event dataEvent Actions - Question #39Incident Response and Threat Investigation
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
taskeng.exescheduled tasksschtasks.exethreat investigation - Question #40Threat Intelligence and MITRE ATT&CK
Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?
MITRE ATT&CKCredential AccessOS Credential Dumpingdetection source - Question #41Prevention Policy Management
What happens when a hash is allowlisted?
hash allowlistingprevention policyCID scopeexecution control - Question #42Investigation and Threat Hunting
The primary purpose for running a Hash Search is to:
hash searchinvestigationthreat huntinghash activity - Question #43Detection Investigation
What does the Full Detection Details option provide?
full detection detailsprocess tree viewprogram ancestrydetection visualization - Question #44Prevention Policy Management
Which option indicates a hash is allowlisted?
hash allowlistingallow actionprevention hashhash status - Question #45Host Management
Where can you find hosts that are in Reduced Functionality Mode?
Reduced Functionality ModeExecutive Summary dashboardhost managementsensor health - Question #46Detection Investigation
When reviewing a Host Timeline, which of the following filters is available?
host timelineevent type filtersinvestigation filterstimeline navigation - Question #47Event Search and Analysis
How does a DNSRequest event link to its responsible process?
DNSRequest eventContextProcessId_decimalprocess correlationevent field mapping - Question #48MITRE ATT&CK Framework
What information does the MITRE ATT&CK Framework provide?
MITRE ATT&CKadversary lifecycleattack techniquesthreat framework - Question #49MITRE ATT&CK Framework
Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?
MITRE ATT&CKpersistencecreate accountFalcon detection taxonomy - Question #50Exclusion Management
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
IOA exclusiondetection suppressionprocess exclusionprevention behavior