CCFR-201 Search Practice Questions
The free CCFR-201: CrowdStrike Certified Falcon Responder questions that deal with search, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
Correct answer: C
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc2. The tool requires two parameters: aid (agent ID) and TargetProcessId_decimal (the decimal value of the process ID)2. These fields can be obtained from any event that involves the process, such as a FileOpenInfo event, which contains information about a file being opened by a process2.
Question #5
What is the difference between a Host Search and a Host Timeline?
Correct answer: A
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Host Search allows you to search for hosts based on various criteria, such as hostname, IP address, OS, etc1. The results are displayed in an organized view by type, such as detections, incidents, processes, network connections, etc1. The Host Timeline allows you to view all events recorded by the sensor for a given host in a chronological order1. The events include process executions, file writes, registry modifications, network connections, user logins, etc1.
Question #8
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in .CSV format?
Correct answer: B
Explanation
According to the CrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, there are three ways to export process event data from a detection in .CSV format1: • You can use the Process Timeline tool and click on ??Export CSV?? button at the top right corner1. • You can use the Event Search tool and select one or more events and click on ??Export CSV?? button at the top right corner1. • You can use the Full Detection Details tool and choose the ??View Process Activity?? option from any process node in the process tree view1. This will show you all events generated bythat process in a rows-and-columns style view1. You can then click on ??Export CSV?? button at the top right corner1.
Continue with CCFR-201: CrowdStrike Certified Falcon Responder
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CCFR-201: CrowdStrike Certified Falcon Responder, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All CCFR-201: CrowdStrike Certified Falcon Responder practice questions →
