Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

CrowdStrike Certified Falcon Responder

Last Update 18 hours ago Total Questions : 209

The CrowdStrike Certified Falcon Responder content is now fully updated, with all current exam questions added 18 hours ago. Deciding to include CCFR-201b practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CCFR-201b exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CCFR-201b sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any CrowdStrike Certified Falcon Responder practice test comfortably within the allotted time.

Question # 1

After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?

A.

SHA256 and TargetProcessld_decimal

B.

SHA256 and ParentProcessld_decimal

C.

aid and ParentProcessld_decimal

D.

aid and TargetProcessld_decimal

Question # 2

In the ' Investigate > Hunt > Linux Sensors ' dashboard, responders can view various Linux-specific activities. Which of the following sub-titling is NOT displayed in this dashboard?

A.

Sudo Executions

B.

Cron Usage

C.

Kernel Module Loads

D.

User Logins

Question # 3

You are pre-staging a Custom IOC for later use and want to save a file hash for later use after approval.

Which action should you use?

A.

Save Hash

B.

Monitor

C.

No Action

D.

Always Block

Question # 4

The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?

A.

Activity

B.

Investigate

C.

Configuration

D.

Dashboards

Question # 5

CrowdStrike supports various deployment types. What is a ' POD sensor ' ?

A.

A sensor specifically designed for mobile devices (iOS/Android).

B.

A sensor that is installed directly on a Kubernetes or Docker host to monitor containers.

C.

A legacy sensor used only for disconnected or air-gapped systems.

D.

A physical appliance that sits on the network to monitor traffic.

Question # 6

A responder needs to find a specific sequence of network connections that did not trigger a detection. Which search tool allows them to search for anything within the raw telemetry?

A.

Host Search

B.

Event Search

C.

Hash Search

D.

User Search

Question # 7

After an investigation, the following malicious artifacts have been identified:

    C:\Users*\AppData\iamnotmalware.exe

    C:\Users*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iamnotmalware.lnk

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iamnotmalware_really

What method will remove all associated artifacts from hosts that trigger future related detections?

A.

Create a Quarantine Rule that will quarantine all identified artifacts across the entire environment

B.

Create Custom IOA rules to prevent the execution of these artifacts

C.

Create a workflow to trigger on a new endpoint detection, query the telemetry data of the endpoint for known artifacts, and select Remove All Associated Artifacts as an action

D.

Create a workflow to trigger on a new endpoint detection, conditions that match the detection, and as an action a PowerShell script to kill associated processes and remove all artifacts

Question # 8

A responder has identified a suspicious PowerShell script executing on a domain controller. To perform a deep-dive forensic analysis of every action taken by that specific process—including network connections and file modifications—the analyst needs to pivot to a Process Timeline. What is the absolute minimum telemetry data required to generate this auto-filled view?

A.

Agent ID (AID) and Local IP Address

B.

Agent ID (AID) and Target Process ID (TargetProcessId_decimal)

C.

Hostname and MAC Address

D.

User SID and SHA256 Hash

Question # 9

Which of the following sentences best describes the primary use of the ' Hash Executions ' Search (Bulk Search)?

A.

It allows a responder to upload a file to the cloud for detonating in a sandbox.

B.

It allows for a summary view of the environment-wide presence of a given list of multiple hashes.

C.

It allows an administrator to block a single hash across all machines.

D.

It provides a detailed process tree for every execution of a single hash.

Question # 10

The User Search results are organized into several categories. Which of the following is NOT a sub-heading in the User Search?

A.

User Logons

B.

Unique Executables Written

C.

Admin tool usage

D.

Network Connections

Go to page: