
Printable & Easy to Use CCFR-201 Dumps 100% Same Q&A In Your Real Exam
CCFR-201 Practice Test Give You First Time Success with 100% Money Back Guarantee!
NEW QUESTION # 26
Which of the following is returned from the IP Search tool?
- A. Threat Graph Data for the given IP from Falcon sensors
- B. IP Summary information from Falcon events containing the given IP
- C. Unmanaged host data from system ARP tables for the given IPD.IP Detection Summary information for detection events containing the given IP
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the IP Search tool allows you to search for an IP address and view a summary of information from Falcon events that contain that IP address1. The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that communicated with that IP address1.
NEW QUESTION # 27
What types of events are returned by a Process Timeline?
- A. Only network events
- B. Only detection events
- C. All cloudable events
- D. Only process events
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline search returns all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc1. This allows you to see a comprehensive view of what a process was doing on a host1.
NEW QUESTION # 28
In the "Full Detection Details", which view will provide an exportable text listing of events like DNS requests.
Registry Operations, and Network Operations?
- A. View as Process Activity
- B. Thedata is unable to be exported
- C. View as Process Timeline
- D. View as Process Tree
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Full Detection Details tool allows you to view detailed information about a detection, such as detection ID, severity, tactic, technique, description, etc1. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity1. The process activity view provides a rows-and-columns style view of the events, such as DNS requests, registry operations, network operations, etc1. You can also export this view to a CSV file for further analysis1.
NEW QUESTION # 29
How long are quarantined files stored on the host?
- A. Quarantined files are never deleted from the host
- B. 90 Days
- C. 45 Days
- D. 30 Days
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, quarantined files are never deleted from the host unless you manually delete them or release them from quarantine2. When you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization2. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud2.
NEW QUESTION # 30
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence.
Which answer best defines Local Prevalence?
- A. Local prevalence is the frequency with which the hash of the triggering file is seen across the entire Internet
- B. Local Prevalence is the Virus Total score for the hash of the triggering file
- C. Local prevalence is the frequency with which the hash of the triggering file is seen across all CrowdStrike customer environments
- D. Local Prevalence tells you how common the hash of the triggering file is within your environment (CID)
Answer: D
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, Global Prevalence and Local Prevalence are two fields that provide information about how common or rare a file is based on its hash value2. Global Prevalence tells you how frequently the hash of the triggering file is seen across all CrowdStrike customer environments2. Local Prevalence tells you how frequently the hash of the triggering file is seen within your environment (CID)2. These fields can help you assess the risk and impact of a detection2.
NEW QUESTION # 31
What happens when you create a Sensor Visibility Exclusion for a trusted file path?
- A. It excludes sensor monitoring and event collection for the trusted file path
- B. It prevents file uploads to the CrowdStrike cloud from that file path
- C. It excludes host information from Detections and Incidents generated within that file path location
- D. It disables detection generation from that path, however the sensor can still perform prevention actions
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, Sensor Visibility Exclusions allow you to exclude certain files or directories from being monitored by the CrowdStrike sensor, which can reduce noise and improve performance2. This means that no events will be collected or sent to the CrowdStrike Cloud for those files or directories2.
NEW QUESTION # 32
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in
.CSV format?
- A. From the Detections Dashboard, you right-click the event type you wish to export and choose CSV.JSON or XML
- B. You can't export detailed event data from a detection, you have to use the Process Timeline or an Event Search
- C. In Full Detection Details, you choose the "View Process Activity" option and then export from that view
- D. In Full Detection Details, you expand the nodes of the process tree you wish to expand and then click the "Export Process Events" button
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, there are three ways to export process event data from a detection in .CSV format1:
You can use the Process Timeline tool and click on "Export CSV" button at the top right corner1.
You can use the Event Search tool and select one or more events and click on "Export CSV" button at the top right corner1.
You can use the Full Detection Details tool and choose the "View Process Activity" option from any process node in the process tree view1. This will show you all events generated bythat process in a rows-and-columns style view1. You can then click on "Export CSV" button at the top right corner1.
NEW QUESTION # 33
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Falcon platform will show a maximum of 1000 detections per day for a single AID1. This is a limitimposed by the Falcon API, which is used to retrieve the detections from the CrowdStrike Cloud1. If there are more than 1000 detections per day for a single AID, only the first 1000 will be shown1.
NEW QUESTION # 34
What action is used when you want to save a prevention hash for later use?
- A. Always Block
- B. No Action
- C. Never Block
- D. Always Allow
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the Always Block action allows you to block a file from executing on any host in your organization based on its hash value2. This action can be used to prevent known malicious files from running on your endpoints2.
NEW QUESTION # 35
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
- A. Draw Process Explorer
- B. Show Associated Event Data (from TargetProcessld_decimal or ContextProcessld_decimal)
- C. Show a +/- 10-minute window of events
- D. Show a Process Timeline for the responsible process
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Event Search tool allows you to search for events based on various criteria, such as event type, timestamp, hostname, IP address, etc1. You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1. However, there is no option to draw a process explorer, which is a graphical representation of the process hierarchy and activity1.
NEW QUESTION # 36
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
- A. SHA256 and TargetProcessld_decimal
- B. aid and TargetProcessld_decimal
- C. SHA256 and ParentProcessld_decimal
- D. aid and ParentProcessld_decimal
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline search requires two parameters: aid (agent ID) and TargetProcessId_decimal (the decimal value of the process ID). These fields can be obtained from the ProcessRollup2 event, which contains information about processes that have executed on a host1.
NEW QUESTION # 37
The Process Activity View provides a rows-and-columns style view of the events generated in a detection.
Why might this be helpful?
- A. The Process Activity View creates a count of event types only, which can be useful when scoping the event
- B. The Process Activity View only creates a summary of Dynamic Link Libraries (DLLs) loaded by a process
- C. The Process Activity View creates a consolidated view of all detection events for that process that can be exported for further analysis
- D. The Process Activity View will show the Detection time of the earliest recorded activity which might indicate first affected machine
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Activity View allows you to view all events generated by a process involved in a detection in a rows-and-columns style view1. This can be helpful because it creates a consolidated view of all detection events for that process that can be exported for further analysis1. You can also sort, filter, and pivot on the events by various fields, such as event type, timestamp, file name, registry key, network destination, etc1.
NEW QUESTION # 38
What is an advantage of using a Process Timeline?
- A. Processes responsible for spikes in CPU performance are displayed overtime
- B. Process related events can be filtered to display specific event types
- C. A visual representation of Parent-Child and Sibling process relationships is provided
- D. Suspicious processes are color-coded based on their frequency and legitimacy over time
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc2. You can also filter the events by various criteria, such as event type, timestamp range, file name, registry key, network destination, etc2. This is an advantage of using the Process Timeline tool because it allows you to focus on specific events that are relevant to your investigation2.
NEW QUESTION # 39
What happens when a hash is allowlisted?
- A. Execution is allowed on all hosts that fall under the organization's CID
- B. The hash is submitted for approval to be allowed to execute once confirmed by Falcon specialists
- C. Execution is prevented, but detection alerts are suppressed
- D. Execution is allowed on all hosts, including all other Falcon customers
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, the allowlist feature allows you to exclude files or directories from being scanned or blocked by CrowdStrike's machine learning engine or indicators of attack (IOAs)2. This can reduce false positives and improve performance2. When you allowlist a hash, you are allowing that file to execute on any host that belongs to your organization's CID (customer ID)2. This does not affect other Falcon customers or hosts outside your CID2.
NEW QUESTION # 40
How long does detection data remain in the CrowdStrike Cloud before purging begins?
- A. 14 Days
- B. 90 Days
- C. 45 Days
- D. 30 Days
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, detection data is stored in the CrowdStrike Cloud for 90 days before purging begins2. This means that you can access and view detections from the past 90 days using the Falcon platform or API2. If you want to retain detection data for longer than 90 days, you can use FDR to replicate it to your own storage system2.
NEW QUESTION # 41
What happens when a quarantined file is released?
- A. It is allowed to execute on all hosts
- B. It is deleted
- C. It is allowed to execute on the host
- D. It is moved into theC:\CrowdStrike\Quarantine\Releasedfolder on the host
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization1. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud1.
NEW QUESTION # 42
You receive an email from a third-party vendor that one of their services is compromised,thevendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?
- A. Hash Executions
- B. Remote or Network Logon Activity
- C. IP Addresses
- D. Remote Access Graph
Answer: C
Explanation:
Explanation
According to the [CrowdStrike website], the Discover page is where you can search for and analyze various types of indicators of compromise (IOCs), such as hashes, IP addresses, or domains that are associated with malicious activities. You can use various tools, such as Hash Executions, IP Addresses, Remote or Network Logon Activity, etc., to perform different types of searches and view the results in different ways. If you want to search for any activity related to an IP address that was compromised by a third-party vendor, you can use the IP Addresses tool to do so. You can input the IP address and see a summary of information from Falcon events that contain that IP address, such as hostname, sensor ID, OS, country, city, ISP, ASN, geolocation, process name, command line, and organizational unit of the host that communicated with that IP address.
NEW QUESTION # 43
When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?
- A. It contains an internal value not useful for an investigation
- B. It contains the TargetProcessld_decimal value for the process that made the DNS request
- C. It contains the ContextProcessld_decimal value for the parent process that made the DNS request
- D. It contains the TargetProcessld_decimal value for other related events
Answer: B
Explanation:
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ContextProcessld_decimal field contains the decimal value of the process ID of the process that generated the event1. This field can be used to trace the process lineage and identify malicious or suspicious activities1. For a DNS request event, this field indicates which process made the DNS request1.
NEW QUESTION # 44
Which is TRUE regarding a file released from quarantine?
- A. It is allowed to execute on all hosts
- B. It will not generate future machine learning detections on the associated host
- C. No executions are allowed for 14 days after release
- D. It is deleted
Answer: A
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you release a file from quarantine, you are restoring it to its original location and allowing it to execute on any host in your organization2. This action also removes the file from the quarantine list and deletes it from the CrowdStrike Cloud2.
NEW QUESTION # 45
Where are quarantined files stored on Windows hosts?
- A. Windows\System32\
- B. Windows\temp\Drivers\CrowdStrike\Quarantine
- C. Windows\System32\Drivers\CrowdStrike\Quarantine
- D. Windows\Quarantine
Answer: C
Explanation:
Explanation
According to the CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide, when you quarantine a file from a host using IOC Management or Real Time Response (RTR), you are moving it from its original location to a secure location on the host where it cannot be executed2. The file is also encrypted and renamed with a random string of characters2. On Windows hosts, quarantined files are stored in C:\Windows\System32\Drivers\CrowdStrike\Quarantine folder2.
NEW QUESTION # 46
What happens when you open the full detection details?
- A. The process explorer opens and the Event Search query is run for the detection
- B. The process explorer opens and the detection copies to the clipboard
- C. Theprocess explorer opens and the detection is removed from the console
- D. The process explorer opens and you're able to view the processes and process relationships
Answer: D
Explanation:
Explanation
According to the [CrowdStrike Falcon Data Replicator (FDR) Add-on for Splunk Guide], when you open the full detection details from a detection alert or dashboard item, you are taken to a page where you can view detailed information about the detection, such as detection ID, severity, tactic, technique, description, etc. You can also view the events generated by the processes involved in the detection in different ways, such as process tree, process timeline, or process activity. The process tree view is also known as the process explorer, which provides a graphical representation of the process hierarchy and activity. You can view the processes and process relationships by expanding or collapsing nodes in the tree. You can also see the event types and timestamps for each process.
NEW QUESTION # 47
......
Fully Updated Free Actual CrowdStrike CCFR-201 Exam Questions: https://www.dumpsreview.com/CCFR-201-exam-dumps-review.html
All Obstacles During CCFR-201 Exam Preparation with CCFR-201 Real Test Questions: https://drive.google.com/open?id=1GXuWo9cIYXkJl-quaCNcL8eKNKTomX7r

