exam questions

Exam CCFA All Questions

View all questions & answers for the CCFA exam

Exam CCFA topic 1 question 9 discussion

Actual exam question from CrowdStrike's CCFA
Question #: 9
Topic #: 1
[All CCFA Questions]

Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?

  • A. Remediation Manager
  • B. Real Time Responder – Read Only Analyst
  • C. Falcon Analyst – Read Only
  • D. Real Time Responder – Active Responder
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
anathi
3 weeks, 1 day ago
Selected Answer: B
B is correct
upvoted 1 times
...
vsnt89
4 months ago
Selected Answer: B
I believe it's the option B. Knowing that only RTR roles allow you to get remote access to a workstation, I assume these are the potential option. Then I read on the documentation that RTR- Responder allows you to extract file and this is not being asked on the question, so I strongly believe that B is the correct option.
upvoted 1 times
...
crowdstrikerz
1 year, 1 month ago
Selected Answer: C
checked
upvoted 1 times
...
Manuneethi
1 year, 5 months ago
Also Falcon Analyst-Ready Only having more options then Real Time Responder-Read Only Analyst according to CrowdStrike Original Console note. You can Falcon Analyst-Read only as one more role. that's it.
upvoted 1 times
...
Manuneethi
1 year, 5 months ago
C Only correct. The question itsellf mentioned Falcon Analyst, he needed additional rights to view all logs. So Falcon Analyst- Read Only Correct
upvoted 1 times
...
Soma7
1 year, 6 months ago
B is correct answer
upvoted 1 times
...
sbag0024
1 year, 6 months ago
Selected Answer: B
B is correct, checked in the docs
upvoted 1 times
...
uday1985
1 year, 7 months ago
B.. confirmed in portal
upvoted 1 times
...
FerbOP
1 year, 8 months ago
Selected Answer: B
B is correct
upvoted 1 times
FerbOP
1 year ago
to get into the system and see the files remotely you need RTR role
upvoted 1 times
...
...
Belrose
1 year, 9 months ago
Selected Answer: B
I Agree, the B is the correct answer. The Falcon Analyst do not have any RTR permission, so it is not able to connect to any host or list files, of course the real time download of files is not allowed. The Real Time Responder - Read Only Analyst only allows to run the commands "cat,cd,clear,env,eventlog,filehash,getsid,help,history,ipconfig,ls,mount,netstat,ps,reg" the role do not have permission to get files so it is the most aproximated profile for the requested capabilities.
upvoted 1 times
...
andreiushu
1 year, 10 months ago
Selected Answer: B
B is the correct answer
upvoted 1 times
...
ShuliAbba
1 year, 11 months ago
I think it would be Real Time Responder - Read Only Analyst. since the RTR admins are probably capable of everything with RTR and RTR Active Responder can extract files from the machine while in the question the ask not to.
upvoted 1 times
...
ShuliAbba
1 year, 11 months ago
@plantvast - but which one?
upvoted 1 times
...
plantvast
1 year, 11 months ago
Selected Answer: B
Questions is talking about viewing files and contents on managed hosts which is only possible using Real-Time Response (RTR).
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago