Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Selected CCFR-201b CCFR Questions Answers

Page: 12 / 16
Total 209 questions

CrowdStrike Certified Falcon Responder Questions and Answers

Question 45

When reviewing open detections, what method should be used to identify the most relevant related information in the environment?

Options:

A.

Host Management grouping by host, organizational unit, or prevention policy

B.

Grouping detections by command line, host, hash, or triggering file

C.

Review the Detection Resolutions dashboard

D.

Sort detections by Time: Oldest to Newest

Question 46

In the ' User Search - File Written ' section, a responder can see various files dropped by a user. Which of the following file types CANNOT be seen from this view?

Options:

A.

Scripts (.ps1, .sh)

B.

Executables (.exe)

C.

Executions (Process starts)

D.

Archive files (.zip, .7z)

Question 47

What is an advantage of using the IP Search tool?

Options:

A.

IP searches provide manufacture and timezone data that can not be accessed anywhere else

B.

IP searches allow for multiple comma separated IPv6 addresses as input

C.

IP searches offer shortcuts to launch response actions and network containment on target hosts

D.

IP searches provide host, process, and organizational unit data without the need to write a query

Question 48

You have a folder with the path C:\Windows\BadTools.

Using native Real Time Response (RTR) commands, what is the correct syntax to remove the folder and all of its contents?

Options:

A.

remove " C:\Windows\BadTools " -all

B.

rm " C:\Windows\BadTools " -force

C.

rm " C:\Windows\BadTools " -rf

D.

remove " C:\Windows\BadTools " -f

Page: 12 / 16
Total 209 questions