Crowdstrike Certified Falcon Responder Free Sample Questions

20 free sample questions218 in the full practice test

Try simulator

CCFR-201 Sample Questions

  1. Question 1

    A Falcon Responder is analyzing a detection where svchost.exe initiated an outbound network connection to a known malicious IP address. The Process Tree shows this svchost.exe instance has no parent process. Which investigative step should be taken next within the Falcon UI to determine the root cause of this suspicious activity?

    Answer and explanation

    Correct answer: B

    When svchost.exe appears without a parent, it is often because it was started as a Windows Service. The Process Tree focuses on direct parent-child relationships and may not show the service creation event. Pivoting to the Host Timeline provides a chronological view of all system events, allowing the responder to identify the service control manager (services.exe) event that created the malicious service, or associated registry keys that define it.

  2. Question 2

    During an investigation, you use the RTR command get C:\Users\Public\artifact.exe. The command fails with an 'access denied' error, even though you have administrative privileges. You suspect the file is locked by a running process. Which sequence of RTR commands is the most effective way to identify the locking process and successfully retrieve the file?

    Answer and explanation

    Correct answer: B

    The most reliable method is to use a custom PowerShell script, such as one that leverages the handle.exe utility or similar functionality, to identify which process has a lock on the file. The runscript command is used to execute such scripts. Once the Process ID (PID) of the locking process is identified, the kill command can be used to terminate it, releasing the lock. Finally, the get command can be successfully executed to retrieve the file.

  3. Question 3

    A financial services firm has a legacy application that exhibits behavior similar to credential dumping but is a legitimate and required part of their quarterly reporting process. This activity generates a high volume of false positive detections, causing analyst fatigue. What is the most precise and secure method to suppress these specific detections without weakening the security posture for the rest of the host?

    Answer and explanation

    Correct answer: C

    An IOA (Indicator of Attack) Exclusion is the most precise tool for this scenario. It allows you to suppress a specific behavioral detection (like credential dumping) but only when it originates from a specific process image name, path, and/or command line. This ensures that if any other process on the system attempts the same malicious behavior, it will still be detected, maintaining a strong security posture. Sensor Visibility Exclusions are too broad, and hash-based allowances don't address behavioral detections.

  4. Question 4

    You are building a custom search query to identify potential lateral movement using PsExec.exe. You want to find instances where PsExec.exe was written to a remote host's ADMIN$ share. Which is the most accurate and efficient search query to accomplish this?

    Answer and explanation

    Correct answer: B

    This query correctly identifies the specific event type for a file being written (event_simpleName=FileWritten), filters for the exact filename of interest (TargetFileName=psexec.exe), and crucially, uses wildcards to specify that the write path must contain the string \\ADMIN\$. This is the most precise way to find PsExec being staged on a remote administrative share.

  5. Question 5

    A responder is reviewing a detection and sees the MITRE ATT&CK Tactic 'TA0003 - Persistence' followed by the Technique 'T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder'. What does this information primarily indicate about the adversary's actions?

    Answer and explanation

    Correct answer: C

    The 'Persistence' tactic (TA0003) describes actions adversaries take to maintain their foothold across restarts, changed credentials, and other interruptions. The specific technique 'T1547.001' details one method of achieving this: placing a program's path in a specific Registry Run Key or a user's Startup Folder, which causes the operating system to automatically execute it when the system starts or a user logs in.

  6. Question 6

    When using the Bulk Domain Search feature, a responder can upload a list of up to 5,000 domains for analysis. True or False: The results of this search will show which hosts in your environment have communicated with those domains within the last 30 days.

    Answer and explanation

    Correct answer: A

    The Bulk Domain Search tool is designed to take a large list of domains and query Falcon's historical event data to identify any endpoints that have made DNS requests for or network connections to those domains. The results provide a list of matching hosts, allowing for rapid scoping of potential compromises.

  7. Question 7

    A responder is analyzing a detection on a Linux server. They need to collect a list of all active network connections, the process associated with each connection, and write the output to a file on the host for later retrieval. Which of the following RTR commands would accomplish this?

    Answer and explanation

    Correct answer: C

    The run command in RTR executes shell commands on the remote host. On Linux, netstat -anp lists all (-a) numeric (-n) network connections and the process (-p) associated with them. The > is the standard shell operator to redirect the output of the command to a file, in this case, /tmp/connections.txt. The >> operator would append, which is not ideal for creating a fresh report.

  8. Question 8

    Multiple answers

    Which of the following pieces of information are available for a given host when viewed from the Host Search results? (Select THREE)

    Answer and explanation

    Correct answers: A, C, D

  9. Question 9

    A security analyst is investigating a complex detection involving multiple processes. After reviewing the Process Tree, they want to understand the exact sequence of all activities performed by a single suspicious process, including file modifications, registry changes, and network connections. Which feature should the analyst pivot to from the detection details?

    Answer and explanation

    Correct answer: B

    The Process Timeline is specifically designed to provide a chronological, filtered view of all events associated with a single process instance (ContextProcessId). This allows the analyst to isolate the actions of one process and see the exact sequence of its activities, which is crucial for understanding its behavior without the noise of other system events. The Host Timeline shows all events on the host, which would be too broad for this specific task.

  10. Question 10

    While analyzing an LsassRead detection, a responder examines the command line of the source process, procdump.exe. The command is procdump.exe -ma lsass.exe C:\temp\lsass.dmp. In this context, what does the external prevalence score of '1' for the procdump.exe hash likely signify?

    Answer and explanation

    Correct answer: C

    procdump.exe is a legitimate utility from Microsoft's Sysinternals suite, used for process diagnostics. However, attackers frequently abuse it to dump credentials from the LSASS process memory. A low external prevalence score (like '1') for the official procdump.exe hash is expected because it's not malware itself and is typically only found on systems where administrators have placed it. The detection is triggered by the behavior (reading LSASS memory), not the file's reputation. This is a classic example of a Living-Off-the-Land Binary (LOLBin) attack.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 218 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon