CCFR-201 Sample Questions

CCFR-201 Sample Questions & Answers

Interpreting the activity dashboard and responding to detections is by far the heaviest topic, alongside the ATT&CK framework from MITRE, process and host timeline investigation, advanced event searching, Real Time Response, and search tools for users, IPs and hashes.

Launch the full CCFR-201 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Search Tools · Analyze the information provided in a Bulk Domain Search

    When using the Bulk Domain Search feature, a responder can upload a list of up to 5,000 domains for analysis. True or False: The results of this search will show which hosts in your environment have communicated with those domains within the last 30 days.

    Show answer & explanation

    Correct answer: A

    The Bulk Domain Search tool is designed to take a large list of domains and query Falcon's historical event data to identify any endpoints that have made DNS requests for or network connections to those domains. The results provide a list of matching hosts, allowing for rapid scoping of potential compromises.

  2. Question 2Intermediate

    Real Time Response (RTR) · Investigate a threat within Falcon and use RTR commands to remediate it

    A responder is analyzing a detection on a Linux server. They need to collect a list of all active network connections, the process associated with each connection, and write the output to a file on the host for later retrieval. Which of the following RTR commands would accomplish this?

    Show answer & explanation

    Correct answer: C

    The run command in RTR executes shell commands on the remote host. On Linux, netstat -anp lists all (-a) numeric (-n) network connections and the process (-p) associated with them. The > is the standard shell operator to redirect the output of the command to a file, in this case, /tmp/connections.txt. The >> operator would append, which is not ideal for creating a fresh report.

  3. Question 3IntermediateSelect 3

    Search Tools · Analyze the information provided in Host Search results

    Which of the following pieces of information are available for a given host when viewed from the Host Search results? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

  4. Question 4Intermediate

    Event Investigation · Understand when to pivot to a Process Timeline or Process Explorer from an Event Search

    A security analyst is investigating a complex detection involving multiple processes. After reviewing the Process Tree, they want to understand the exact sequence of all activities performed by a single suspicious process, including file modifications, registry changes, and network connections. Which feature should the analyst pivot to from the detection details?

    Show answer & explanation

    Correct answer: B

    The Process Timeline is specifically designed to provide a chronological, filtered view of all events associated with a single process instance (ContextProcessId). This allows the analyst to isolate the actions of one process and see the exact sequence of its activities, which is crucial for understanding its behavior without the noise of other system events. The Host Timeline shows all events on the host, which would be too broad for this specific task.

  5. Question 5Intermediate

    Detection Analysis · Evaluate the impact of internal and external prevalance

    While analyzing an LsassRead detection, a responder examines the command line of the source process, procdump.exe. The command is procdump.exe -ma lsass.exe C:\temp\lsass.dmp. In this context, what does the external prevalence score of '1' for the procdump.exe hash likely signify?

    Show answer & explanation

    Correct answer: C

    procdump.exe is a legitimate utility from Microsoft's Sysinternals suite, used for process diagnostics. However, attackers frequently abuse it to dump credentials from the LSASS process memory. A low external prevalence score (like '1') for the official procdump.exe hash is expected because it's not malware itself and is typically only found on systems where administrators have placed it. The detection is triggered by the behavior (reading LSASS memory), not the file's reputation. This is a classic example of a Living-Off-the-Land Binary (LOLBin) attack.

  6. Question 6Advanced

    Detection Analysis · Recommend courses of action based on the analysis of information provided with Falcon

    Case Study

    A healthcare organization's SOC team receives a high-severity alert from the CrowdStrike Falcon console on a critical patient records server. The detection is for a PowerShell script that established a network connection to an unknown IP address, downloaded a file named update.dll, and then executed it using rundll32.exe. The Process Tree confirms this sequence of events, originating from a non-interactive service account.

    Initial triage reveals that the IP address has no reputation in VirusTotal, but a Hash Search on update.dll shows zero prevalence both internally and externally. The service account is a legacy account used by an old data transfer application. The responder immediately contains the host to prevent further damage. The primary objectives now are to understand the full scope of the compromise, identify the initial access vector, and ensure no other systems are affected.

    Which combination of actions represents the most logical and comprehensive next steps for the investigation?

    Show answer & explanation

    Correct answer: B

    This set of actions addresses all primary objectives. A User Search on the compromised service account will reveal if it was used elsewhere (scoping). Searching for all powershell.exe executions helps identify similar attack patterns on other systems. A Bulk IP search for the attacker's IP will quickly determine if any other hosts have communicated with it. These steps effectively use Falcon's tools to expand the investigation from a single host to the entire environment to understand the full scope.

  7. Question 7Intermediate

    Real Time Response (RTR) · Set up a Workflow with RTR custom scripts

    A responder is creating a workflow using RTR custom scripts to automate the collection of forensic artifacts from a contained Windows host. The workflow needs to execute a PowerShell script named Triage-Collection.ps1 which is already uploaded to the cloud library. Which RTR command should be used within the workflow to execute this script?

    Show answer & explanation

    Correct answer: C

    The runscript command is the designated RTR command for executing scripts from the cloud library (Response Scripts and Files). The -CloudFile parameter specifies the name of the script to be executed on the target host. The standard run command is for built-in shell commands and cannot execute scripts from the cloud library directly.

  8. Question 8Beginner

    Detection Analysis · Apply best practices to quarantined files

    A file quarantined by Falcon on a Windows host is stored in a protected directory to prevent tampering. An analyst needs to retrieve this file for further analysis. They should use the get command in RTR to retrieve the file from which default directory?

    Show answer & explanation

    Correct answer: C

    On Windows systems, the Falcon sensor stores quarantined files in the C:\Windows\System32\drivers\CrowdStrike\Quarantine\ directory. Knowing this path is essential for manual retrieval using RTR if the standard 'Download Quarantined File' UI option is unavailable or if a scripted approach is needed.

  9. Question 9Beginner

    Real Time Response (RTR) · Review audit logs to audit RTR activity

    A security manager asks a responder to provide an audit trail of all Real Time Response sessions initiated by the SOC team in the past week, including who initiated the session and which commands were run. Where can the responder find this information in the Falcon console?

    Show answer & explanation

    Correct answer: C

    CrowdStrike provides a dedicated audit log for all Real Time Response activities to ensure accountability and provide a clear record of actions taken on endpoints. This log, found under the Real Time Response section of Host Management, captures details such as the user who initiated the session, the target host, the session start and end times, and a full list of commands executed.

  10. Question 10Beginner

    Search Tools · Analyze the information provided in a User Search

    What is the primary difference between the information provided by a User Search and a Host Search in the Falcon console?

    Show answer & explanation

    Correct answer: B

    A User Search provides a user-centric view, aggregating data like successful and failed logons, account lockouts, and password changes for a specific user account across the entire environment. A Host Search provides a host-centric view, showing details like OS version, sensor health, IP addresses, and applied policies for a single machine.

Ready for the real thing?

The full CCFR-201 simulator has every exam-style question, timed mode, and instant scoring.