CCFR-201B Exam Questions
70 real CCFR-201B exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Detection Investigation
What is an advantage of using a Process Timeline?
process timelineevent type filteringinvestigationprocess events - Question #52Prevention Policy Management
What action is used when you want to save a prevention hash for later use?
prevention hashno actionhash managementhash save - Question #53Investigation and Threat Hunting
You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would...
IP investigationindicator searchthreat huntingFalcon Investigate - Question #54Event Search and Analysis
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenInfo event and want to find out if any other files were opened by the responsible proces...
event searchContextProcessId_decimalaid fieldprocess timeline search - Question #55Quarantine Management
How long are quarantined files stored in the CrowdStrike Cloud?
quarantinefile retentioncloud storagequarantine duration - Question #56Investigation and Threat Hunting
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request informatio...
domain investigationFalcon Investigatemalicious domainnetwork threat hunting - Question #57Detection Investigation
What information is contained within a Process Timeline?
process timelinecloudable eventsprocess activityinvestigation scope - Question #58Exclusion Management
Sensor Visibility Exclusion patterns are written in which syntax?
sensor visibility exclusionglob syntaxexclusion patternssensor configuration - Question #59Detection Investigation
In the "Full Detection Details", which view will provide an exportable text listing of events like DNS requests. Registry Operations, and Network Operations?
process activity viewdetection exportevent listingDNS and registry operations - Question #60Quarantine Management
What happens when a quarantined file is released?
quarantinefile releaseexecution restorationquarantine actions - Question #61Threat Investigation and Search
Advanced Event Search in Falcon supports a look-back period of up to __________ days depending on the retention policy.
Advanced Event Searchevent retentionlook-back periodlog retention policy - Question #62Detection Management
Which two detection filtering options are available in the Endpoint Security > Endpoint Detections page? (Choose two)
endpoint detectionsdetection filteringtactic filterhost group filter - Question #63Incident Response
What would be a logical next step after identifying an unmanaged host in Host Search?
unmanaged hosthost investigationcontainmentincident response workflow - Question #64Threat Investigation and Search
Which search type should be used to investigate whether a suspicious executable has affected multiple hosts?
Hash Searchexecutable investigationmulti-host analysissearch types - Question #65Threat Investigation and Search
When reviewing an internal IP address via IP Search, which fields would help determine potential lateral movement? (Choose two)
IP Searchlateral movementconnected hostsdestination IPs - Question #66Real Time Response
What is the default port used by Falcon RTR to establish a connection with a managed host?
Real Time ResponseRTRport 443network connectivity - Question #67Detection Management
Which Falcon feature allows responders to assign specific actions to detections such as "Allow" or "Block and Hide"?
detection actionsallow/blockhost management actionsdetection workflow - Question #68Threat Investigation and Search
User Search can help correlate suspicious behavior by showing all of the following except:
User Searchuser activity correlationsearch scopedetection events - Question #69Threat Investigation and Search
You're investigating suspicious behavior linked to a user. Which key indicators should you examine in the User Search view to assess the threat context? (Choose two)
User Searchthreat contextdetection counthost access history - Question #70Detection Management
When viewing detection information, which component provides granular details like command- line arguments and file paths?
Full Detection Viewdetection detailscommand-line argumentsfile paths