Brilliant CCFR-201 Exam Dumps Get CCFR-201 Dumps PDF [Q36-Q51]

Share

Brilliant CCFR-201 Exam Dumps Get CCFR-201 Dumps PDF

CCFR-201 Dumps PDF - CCFR-201 Real Exam Questions Answers

NEW QUESTION # 36
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?

  • A. A managed neighbor has an installed and provisioned sensor
  • B. A managed sensor has an active prevention policy
  • C. A managed neighbor is currently network contained and an unmanaged neighbor is uncontained
  • D. An unmanaged neighbor is in a segmented area of the network

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, you can use the Hosts page in the Investigate tool to view information about your endpoints, such as hostname, IP address, OS, sensor version, etc2. You can also see a list of managed and unmanaged neighbors for each endpoint, which are other devices that have communicated with that endpoint over the network2. A managed neighbor is a device that has an installed and provisioned sensor that reports to the CrowdStrike Cloud2. An unmanaged neighbor is a device that does not have an installed or provisioned sensor2.


NEW QUESTION # 37
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?

  • A. Show a +/- 10-minute window of events
  • B. Draw Process Explorer
  • C. Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)
  • D. Show a Process Timeline for the responsible process

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Event Search tool allows you to search for events based on various criteria, such as event type, timestamp, hostname, IP address, etc1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. However, there is no option to draw a process explorer, which is a graphical representation of the process hierarchy and activity1.


NEW QUESTION # 38
Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?

  • A. Machine Learning via Cloud-Based ML
  • B. Malware via PUP
  • C. Falcon Intel via Intelligence Indicator - Domain
  • D. Credential Access via OS Credential Dumping

Answer: D

Explanation:
Explanation
According to the [MITRE ATT&CK website], MITRE ATT&CK is a knowledge base of adversary behaviors and techniques based on real-world observations. The knowledge base is organized into tactics and techniques, where tactics are the high-level goals of an adversary, such as initial access, persistence, lateral movement, etc., and techniques are the specific ways an adversary can achieve those goals, such as phishing, credential dumping, remote file copy, etc. Credential Access via OS Credential Dumping is an example of a tactic and technique combination sourced from MITRE ATT&CK information, which describes how adversaries can obtain credentials from operating system memory or disk storage by using tools such as Mimikatz or ProcDump.


NEW QUESTION # 39
What happens when you create a Sensor Visibility Exclusion for a trusted file path?

  • A. It excludes sensor monitoring and event collection for the trusted file path
  • B. It disables detection generation from that path, however the sensor can still perform prevention actions
  • C. It prevents file uploads to the CrowdStrike cloud from that file path
  • D. It excludes host information from Detections and Incidents generated within that file path location

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, Sensor Visibility Exclusions allow you to exclude certain files or directories from being monitored by the CrowdStrike sensor, which can reduce noise and improve performance2. This means that no events will be collected or sent to the CrowdStrike Cloud for those files or directories2.


NEW QUESTION # 40
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Falcon platform will show a maximum of 1000 detections per day for a single AID1. This is a limitimposed by the Falcon API, which is used to retrieve the detections from the CrowdStrike Cloud1. If there are more than 1000 detections per day for a single AID, only the first 1000 will be shown1.


NEW QUESTION # 41
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?

  • A. It contains the TargetProcessld_decimal value of the child process
  • B. It contains the Sensorld_decimal value for related events
  • C. It contains an internal value not useful for an investigation
  • D. It contains the TargetProcessld_decimal of the parent process

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ParentProcessld_decimal field contains the decimal value of the process ID of the parent process that spawned or injected into the target process1. This field can be used to trace the process lineage and identify malicious or suspicious activities1.


NEW QUESTION # 42
How long does detection data remain in the CrowdStrike Cloud before purging begins?

  • A. 30 Days
  • B. 14 Days
  • C. 45 Days
  • D. 90 Days

Answer: D

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, detection data is stored in the CrowdStrike Cloud for 90 days before purging begins2. This means that you can access and view detections from the past 90 days using the Falcon platform or API2. If you want to retain detection data for longer than 90 days, you can use FDR to replicate it to your own storage system2.


NEW QUESTION # 43
What happens when a hash is allowlisted?

  • A. Execution is allowed on all hosts that fall under the organization's CID
  • B. Execution is prevented, but detection alerts are suppressed
  • C. The hash is submitted for approval to be allowed to execute once confirmed by Falcon specialists
  • D. Execution is allowed on all hosts, including all other Falcon customers

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the allowlist feature allows you to exclude files or directories from being scanned or blocked by CrowdStrike's machine learning engine or indicators of attack (IOAs)2. This can reduce false positives and improve performance2. When you allowlist a hash, you are allowing that file to execute on any host that belongs to your organization's CID (customer ID)2. This does not affect other Falcon customers or hosts outside your CID2.


NEW QUESTION # 44
Where are quarantined files stored on Windows hosts?

  • A. Windows\Quarantine
  • B. Windows\System32\Drivers\CrowdStrike\Quarantine
  • C. Windows\System32\
  • D. Windows\temp\Drivers\CrowdStrike\Quarantine

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.


NEW QUESTION # 45
The Process Activity View provides a rows-and-columns style view of the events generated in a detection.
Why might this be helpful?

  • A. The Process Activity View creates a consolidated view of all detection events for that process that can be exported for further analysis
  • B. The Process Activity View only creates a summary of Dynamic Link Libraries (DLLs) loaded by a process
  • C. The Process Activity View creates a count of event types only, which can be useful when scoping the event
  • D. The Process Activity View will show the Detection time of the earliest recorded activity which might indicate first affected machine

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Activity View allows you to view all events generated by a process involved in a detection in a rows-and-columns style view1. This can be helpful because it creates a consolidated view of all detection events for that process that can be exported for further analysis1. You can also sort, filter, and pivot on the events by various fields, such as event type, timestamp, file name, registry key, network destination, etc1.


NEW QUESTION # 46
What happens when a quarantined file is released?

  • A. It is allowed to execute on all hosts
  • B. It is allowed to execute on the host
  • C. It is deleted
  • D. It is moved into theC:\CrowdStrike\Quarantine\Releasedfolder on the host

Answer: A

Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization1. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud1.


NEW QUESTION # 47
Which Executive Summary dashboard item indicates sensors running with unsupported versions?

  • A. Detections by Severity
  • B. Inactive Sensors
  • C. Sensors in RFM
  • D. Active Sensors

Answer: C

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Executive Summary dashboard provides an overview of your sensor health and activity1. It includes various items, such as Active Sensors, Inactive Sensors, Detections by Severity, etc1. The item that indicates sensors running with unsupported versions is Sensors in RFM (Reduced Functionality Mode)1. RFM is a state where a sensor has limited functionality due to various reasons, such as license expiration, network issues, tampering attempts, or unsupported versions1. You can see the number and percentage of sensors in RFM and the reasons why they are in RFM1.


NEW QUESTION # 48
Which statement is TRUE regarding the "Bulk Domains" search?

  • A. The "Bulk Domains" search will show IP address and port information for any associated connectionsD.You should only pivot to the "Bulk Domains" search tool after completing an investigation
  • B. It will show a list of computers and process that performed a lookup of any of the domains in your search
  • C. The "Bulk Domains" search will allow you to blocklist your queried domains

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Bulk Domain Search tool allows you to search for one or more domains and view a summary of information from Falcon events that contain those domains2. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that performed a lookup of any of the domains in your search2. This can help you identify potential threats or vulnerabilities in your network2.


NEW QUESTION # 49
What does pivoting to an Event Search from a detection do?

  • A. It takes you to a Process Timeline for that detection so you can see all related events
  • B. It takes you to the raw Insight event data and provides you with a number of Event Actions
  • C. It gives you the ability to search for similar events on other endpoints quickly
  • D. It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection

Answer: B

Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, pivoting to an Event Search from a detection takes you to the raw Insight event data and provides you with a number of Event Actions1. Insight events are low-level events that are generated by the sensor for various activities, such as process executions, file writes, registry modifications, network connections, etc1. You can view these events in a table format and use various filters and fields to narrow down the results1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. These actions can help you investigate and analyze events more efficiently and effectively1.


NEW QUESTION # 50
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?

  • A. Executions of schtasks.exe after the detection
  • B. Pivot to a Hash search for taskeng.exe
  • C. User logons after the detection
  • D. Scheduled tasks registered prior to the detection

Answer: D

Explanation:
Explanation
According to the [Microsoft website], taskeng.exe is a legitimate Windows process that is responsible for running scheduled tasks. However, some malware may use this process or create a fake one to execute malicious code. Therefore, if you notice taskeng.exe involved in a detection, you should investigate whether there are any scheduled tasks registered prior to the detection that may have triggered or injected into taskeng.exe. You can use tools such as schtasks.exe or Task Scheduler to view or manage scheduled tasks.


NEW QUESTION # 51
......

Valid CCFR-201 Test Answers & CrowdStrike CCFR-201 Exam PDF: https://examsboost.pass4training.com/CCFR-201-test-questions.html