Pass the CrowdStrike CCFR CCFR-201 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

In the Hash Search tool, which of the following is listed under Process Executions?

Options:

A.

Operating System


B.

File Signature


C.

Command Line


D.

Sensor Version


Expert Solution
Questions # 12:

Which statement is TRUE regarding the "Bulk Domains" search?

Options:

A.

It will show a list of computers and process that performed a lookup of any of the domains in your search


B.

The "Bulk Domains" search will allow you to blocklist your queried domains


C.

The "Bulk Domains" search will show IP address and port information for any associated connectionsD.You should only pivot to the "Bulk Domains" search tool after completing an investigation


Expert Solution
Questions # 13:

Sensor Visibility Exclusion patterns are written in which syntax?

Options:

A.

Glob Syntax


B.

Kleene Star Syntax


C.

RegEx


D.

SPL(Splunk)


Expert Solution
Questions # 14:

When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?

Options:

A.

It contains the TargetProcessld_decimal value for other related events


B.

It contains an internal value not useful for an investigation


C.

It contains the ContextProcessld_decimal value for the parent process that made the DNS request


D.

It contains the TargetProcessld_decimal value for the process that made the DNS request


Expert Solution
Questions # 15:

The Bulk Domain Search tool contains Domain information along with which of the following?

Options:

A.

Process Information


B.

Port Information


C.

IP Lookup Information


D.

Threat Actor Information


Expert Solution
Questions # 16:

After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?

Options:

A.

Draw Process Explorer


B.

Show a +/- 10-minute window of events


C.

Show a Process Timeline for the responsible process


D.

Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)


Expert Solution
Questions # 17:

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?

Options:

A.

ParentProcessld_decimal and aid


B.

ResponsibleProcessld_decimal and aid


C.

ContextProcessld_decimal and aid


D.

TargetProcessld_decimal and aid


Expert Solution
Questions # 18:

You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?

Options:

A.

ProcessTimeline Link


B.

PID


C.

UTCtime


D.

Process ID or Parent Process ID


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions