CCFR-201 Crowdstrike Certified Falcon Responder Practice Questions
Prepare for CCFR-201 with more than an answer.
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- ATT&CK Framework Application10%
- Detection Analysis35%
- Event Search10%
- Event Investigation15%
- Search Tools15%
- Real Time Response (RTR)15%
- 1
A responder is analyzing the following process relationship discovered in a detection's Process Tree. Based on this diagram, which process is the most likely candidate for the initial point of compromise on the endpoint?
graph TD A[outlook.exe] --> B[winword.exe]; B --> C[eqnedt32.exe]; C --> D[cmd.exe]; D --> E[powershell.exe];Show answer details
Correct answer: A
The diagram shows a classic spear-phishing attack chain. The user opens an email in
outlook.exe, which contains a malicious Word document, launchingwinword.exe. The Word document exploits a vulnerability in the old Equation Editor (eqnedt32.exe), which then spawns a command shell (cmd.exe) to execute a PowerShell payload (powershell.exe). The root of this entire chain isoutlook.exe, representing the initial entry vector via a malicious email. - 2
A detection is generated for a process that wrote a file with a specific hash. A responder wants to quickly determine if this same file exists on any other hosts in the environment. Which Falcon search tool is the most direct and efficient way to achieve this?
Show answer details
Correct answer: D
The Hash Search tool is specifically designed for this purpose. By inputting an MD5, SHA1, or SHA256 hash, a responder can query the Falcon platform to see a list of all endpoints where a file with that exact hash has been observed. This is the most efficient method for scoping the presence of a specific malicious file across the enterprise.
- 3
A new detection is assigned to you. The detection source is listed as 'ML-Based Prevention'. What does this indicate about the nature of the prevented activity?
Show answer details
Correct answer: C
'ML-Based Prevention' signifies that CrowdStrike's machine learning engine analyzed the static attributes of a file (without executing it) and determined it to be malicious. This is a key component of next-generation antivirus (NGAV) capabilities, allowing Falcon to block zero-day malware that does not have a known signature or hash.
- 4
Which of the following are valid Hash Management Actions that can be applied to a custom IOC in the Falcon console? (Select TWO)
Show answer details
Correct answer: B, C
- 5
The RTR command
reg queryis used to query the Windows Registry, but it cannot be used to modify registry values. True or False?Show answer details
Correct answer: B
This statement is false. While
reg queryis for reading registry values, RTR also provides commands likereg setandreg deletewhich allow a responder with appropriate privileges to modify and delete registry keys and values, which is a critical capability for remediating persistence mechanisms. - 6
A Falcon Responder is analyzing a detection where
svchost.exeinitiated an outbound network connection to a known malicious IP address. The Process Tree shows thissvchost.exeinstance has no parent process. Which investigative step should be taken next within the Falcon UI to determine the root cause of this suspicious activity?Show answer details
Correct answer: B
When
svchost.exeappears without a parent, it is often because it was started as a Windows Service. The Process Tree focuses on direct parent-child relationships and may not show the service creation event. Pivoting to the Host Timeline provides a chronological view of all system events, allowing the responder to identify the service control manager (services.exe) event that created the malicious service, or associated registry keys that define it. - 7
During an investigation, you use the RTR command
get C:\Users\Public\artifact.exe. The command fails with an 'access denied' error, even though you have administrative privileges. You suspect the file is locked by a running process. Which sequence of RTR commands is the most effective way to identify the locking process and successfully retrieve the file?Show answer details
Correct answer: B
The most reliable method is to use a custom PowerShell script, such as one that leverages the
handle.exeutility or similar functionality, to identify which process has a lock on the file. Therunscriptcommand is used to execute such scripts. Once the Process ID (PID) of the locking process is identified, thekillcommand can be used to terminate it, releasing the lock. Finally, thegetcommand can be successfully executed to retrieve the file. - 8
A financial services firm has a legacy application that exhibits behavior similar to credential dumping but is a legitimate and required part of their quarterly reporting process. This activity generates a high volume of false positive detections, causing analyst fatigue. What is the most precise and secure method to suppress these specific detections without weakening the security posture for the rest of the host?
Show answer details
Correct answer: C
An IOA (Indicator of Attack) Exclusion is the most precise tool for this scenario. It allows you to suppress a specific behavioral detection (like credential dumping) but only when it originates from a specific process image name, path, and/or command line. This ensures that if any other process on the system attempts the same malicious behavior, it will still be detected, maintaining a strong security posture. Sensor Visibility Exclusions are too broad, and hash-based allowances don't address behavioral detections.
- 9
You are building a custom search query to identify potential lateral movement using
PsExec.exe. You want to find instances wherePsExec.exewas written to a remote host's ADMIN$ share. Which is the most accurate and efficient search query to accomplish this?Show answer details
Correct answer: B
This query correctly identifies the specific event type for a file being written (
event_simpleName=FileWritten), filters for the exact filename of interest (TargetFileName=psexec.exe), and crucially, uses wildcards to specify that the write path must contain the string\\ADMIN\$. This is the most precise way to find PsExec being staged on a remote administrative share. - 10
A responder is reviewing a detection and sees the MITRE ATT&CK Tactic 'TA0003 - Persistence' followed by the Technique 'T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder'. What does this information primarily indicate about the adversary's actions?
Show answer details
Correct answer: C
The 'Persistence' tactic (TA0003) describes actions adversaries take to maintain their foothold across restarts, changed credentials, and other interruptions. The specific technique 'T1547.001' details one method of achieving this: placing a program's path in a specific Registry Run Key or a user's Startup Folder, which causes the operating system to automatically execute it when the system starts or a user logs in.
