Skip to content

CCFR-201 Crowdstrike Certified Falcon Responder Practice Questions

Prepare for CCFR-201 with more than an answer.

218 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 6
  1. ATT&CK Framework Application10%
  2. Detection Analysis35%
  3. Event Search10%
  4. Event Investigation15%
  5. Search Tools15%
  6. Real Time Response (RTR)15%
  1. 1

    A responder is analyzing the following process relationship discovered in a detection's Process Tree. Based on this diagram, which process is the most likely candidate for the initial point of compromise on the endpoint?

    graph TD A[outlook.exe] --> B[winword.exe]; B --> C[eqnedt32.exe]; C --> D[cmd.exe]; D --> E[powershell.exe];

    Show answer details

    Correct answer: A

    The diagram shows a classic spear-phishing attack chain. The user opens an email in outlook.exe, which contains a malicious Word document, launching winword.exe. The Word document exploits a vulnerability in the old Equation Editor (eqnedt32.exe), which then spawns a command shell (cmd.exe) to execute a PowerShell payload (powershell.exe). The root of this entire chain is outlook.exe, representing the initial entry vector via a malicious email.

  2. 2

    A detection is generated for a process that wrote a file with a specific hash. A responder wants to quickly determine if this same file exists on any other hosts in the environment. Which Falcon search tool is the most direct and efficient way to achieve this?

    Show answer details

    Correct answer: D

    The Hash Search tool is specifically designed for this purpose. By inputting an MD5, SHA1, or SHA256 hash, a responder can query the Falcon platform to see a list of all endpoints where a file with that exact hash has been observed. This is the most efficient method for scoping the presence of a specific malicious file across the enterprise.

  3. 3

    A new detection is assigned to you. The detection source is listed as 'ML-Based Prevention'. What does this indicate about the nature of the prevented activity?

    Show answer details

    Correct answer: C

    'ML-Based Prevention' signifies that CrowdStrike's machine learning engine analyzed the static attributes of a file (without executing it) and determined it to be malicious. This is a key component of next-generation antivirus (NGAV) capabilities, allowing Falcon to block zero-day malware that does not have a known signature or hash.

  4. 4

    Which of the following are valid Hash Management Actions that can be applied to a custom IOC in the Falcon console? (Select TWO)

    Show answer details

    Correct answer: B, C

  5. 5

    The RTR command reg query is used to query the Windows Registry, but it cannot be used to modify registry values. True or False?

    Show answer details

    Correct answer: B

    This statement is false. While reg query is for reading registry values, RTR also provides commands like reg set and reg delete which allow a responder with appropriate privileges to modify and delete registry keys and values, which is a critical capability for remediating persistence mechanisms.

  6. 6

    A Falcon Responder is analyzing a detection where svchost.exe initiated an outbound network connection to a known malicious IP address. The Process Tree shows this svchost.exe instance has no parent process. Which investigative step should be taken next within the Falcon UI to determine the root cause of this suspicious activity?

    Show answer details

    Correct answer: B

    When svchost.exe appears without a parent, it is often because it was started as a Windows Service. The Process Tree focuses on direct parent-child relationships and may not show the service creation event. Pivoting to the Host Timeline provides a chronological view of all system events, allowing the responder to identify the service control manager (services.exe) event that created the malicious service, or associated registry keys that define it.

  7. 7

    During an investigation, you use the RTR command get C:\Users\Public\artifact.exe. The command fails with an 'access denied' error, even though you have administrative privileges. You suspect the file is locked by a running process. Which sequence of RTR commands is the most effective way to identify the locking process and successfully retrieve the file?

    Show answer details

    Correct answer: B

    The most reliable method is to use a custom PowerShell script, such as one that leverages the handle.exe utility or similar functionality, to identify which process has a lock on the file. The runscript command is used to execute such scripts. Once the Process ID (PID) of the locking process is identified, the kill command can be used to terminate it, releasing the lock. Finally, the get command can be successfully executed to retrieve the file.

  8. 8

    A financial services firm has a legacy application that exhibits behavior similar to credential dumping but is a legitimate and required part of their quarterly reporting process. This activity generates a high volume of false positive detections, causing analyst fatigue. What is the most precise and secure method to suppress these specific detections without weakening the security posture for the rest of the host?

    Show answer details

    Correct answer: C

    An IOA (Indicator of Attack) Exclusion is the most precise tool for this scenario. It allows you to suppress a specific behavioral detection (like credential dumping) but only when it originates from a specific process image name, path, and/or command line. This ensures that if any other process on the system attempts the same malicious behavior, it will still be detected, maintaining a strong security posture. Sensor Visibility Exclusions are too broad, and hash-based allowances don't address behavioral detections.

  9. 9

    You are building a custom search query to identify potential lateral movement using PsExec.exe. You want to find instances where PsExec.exe was written to a remote host's ADMIN$ share. Which is the most accurate and efficient search query to accomplish this?

    Show answer details

    Correct answer: B

    This query correctly identifies the specific event type for a file being written (event_simpleName=FileWritten), filters for the exact filename of interest (TargetFileName=psexec.exe), and crucially, uses wildcards to specify that the write path must contain the string \\ADMIN\$. This is the most precise way to find PsExec being staged on a remote administrative share.

  10. 10

    A responder is reviewing a detection and sees the MITRE ATT&CK Tactic 'TA0003 - Persistence' followed by the Technique 'T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder'. What does this information primarily indicate about the adversary's actions?

    Show answer details

    Correct answer: C

    The 'Persistence' tactic (TA0003) describes actions adversaries take to maintain their foothold across restarts, changed credentials, and other interruptions. The specific technique 'T1547.001' details one method of achieving this: placing a program's path in a specific Registry Run Key or a user's Startup Folder, which causes the operating system to automatically execute it when the system starts or a user logs in.

Create an account to continue.