Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
sale

Want to Unlock All Questions for this Exam?

Full Exam Access, Discussions, No Robots Checks

CrowdStrike CCFR-201 Exam Actual Questions

The questions for CCFR-201 were last updated on May 15, 2024.
  • Viewing page 1 out of 15 pages.
  • Viewing questions 1-4 out of 60 questions

Topic 1 - Exam A

Question #1 Topic 1

Where can you find hosts that are in Reduced Functionality Mode?

  • A. Event Search
  • B. Executive Summary dashboard
  • C. Host Search
  • D. Installation Tokens
Reveal Solution Hide Solution   Discussion   5

Correct Answer: C 🗳️

Question #2 Topic 1

When reviewing a Host Timeline, which of the following filters is available?

  • A. Severity
  • B. Event Types
  • C. User Name
  • D. Detection ID
Reveal Solution Hide Solution   Discussion   2

Correct Answer: B 🗳️

Question #3 Topic 1

How does a DNSRequest event link to its responsible process?

  • A. Via both its ContextProcessId_decimal and ParentProcessId_decimal fields
  • B. Via its ParentProcessId_decimal field
  • C. Via its ContextProcessId_decimal field
  • D. Via its TargetProcessId_decimal field
Reveal Solution Hide Solution   Discussion   5

Correct Answer: C 🗳️

Question #4 Topic 1

What information does the MITRE ATT&CK Framework provide?

  • A. It provides best practices for different cybersecurity domains, such as Identify and Access Management
  • B. It provides a step-by-step cyber incident response strategy
  • C. It provides the phases of an adversary's lifecycle, the platforms they are known to attack, and the specific methods they use
  • D. It is a system that attributes attack techniques to a specific threat actor
Reveal Solution Hide Solution   Discussion   2

Correct Answer: C 🗳️

Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...