Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CrowdStrike CCFR CCFR-201b Questions and answers with CertsForce

Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions
Questions # 31:

When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?

Options:

A.

Do nothing, as this file is common and well known


B.

From detection, click the VT Hash button to pivot to VirusTotal to investigate further


C.

From detection, use API manager to create a custom blocklist


D.

From detection, submit to FalconX for deep dive analysis


Expert Solution
Questions # 32:

How long are quarantined files stored in the CrowdStrike Cloud?

Options:

A.

45 Days


B.

90 Days


C.

Days


D.

Quarantined files are not deleted


Expert Solution
Questions # 33:

Host Search is a powerful investigation tool. From which of the following sources is a responder most likely to pivot directly to a Host Search?

Options:

A.

A global intelligence report about a new adversary.


B.

A specific detection that occurred on a particular host.


C.

The main settings menu of the Falcon console.


D.

The help documentation in the Support portal.


Expert Solution
Questions # 34:

The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?

Options:

A.

Activity


B.

Investigate


C.

Configuration


D.

Dashboards


Expert Solution
Questions # 35:

The Falcon sensor is designed to provide deep visibility into endpoint activity, yet it is not omniscient. According to the Cyber Kill Chain model, which of the following stages does the Falcon sensor typically NOT have visibility over?

Options:

A.

Exploitation of a memory-resident vulnerability


B.

Installation of a persistent backdoor


C.

Weaponization of a malicious payload on the adversary ' s infrastructure


D.

Delivery of a malicious document via an encrypted email attachment


Expert Solution
Questions # 36:

During the configuration of a new IOA rule, the administrator must decide what action the sensor should take. Which of the following is NOT a valid IOA rule action?

Options:

A.

Monitor


B.

Block


C.

No Action


D.

Kill Process


Expert Solution
Questions # 37:

When a responder is looking at the ' Full Detection Details ' page, they can toggle between several views. Which of the following is NOT a layout option available for viewing these details?

Options:

A.

Graph View


B.

Tree View


C.

Process Timeline


D.

List View


Expert Solution
Questions # 38:

By default, when a file is quarantined by the Falcon sensor to prevent execution, how many days does that file remain on the host ' s local disk?

Options:

A.

7 days


B.

14 days


C.

30 days


D.

90 days


Expert Solution
Questions # 39:

Which of the following subtitles/sub-views cannot be seen in the results of a ' Hash Search ' ?

Options:

A.

File Metadata


B.

Process Timeline


C.

Intel Indicators


D.

Execution History


Expert Solution
Questions # 40:

A security analyst is triaging a high-severity alert on a critical production server. To understand the adversary ' s intent and technical execution within the framework of industry standards, the analyst refers to the console ' s categorization. Which specific methodology does CrowdStrike utilize within the Falcon platform to classify detections based on technical behavior?

Options:

A.

MITRE-Based Falcon Detections Framework


B.

NIST Incident Response Lifecycle


C.

Falcon Adversary Attribution Matrix


D.

Cyber Kill Chain Classification


Expert Solution
Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions