CrowdStrike
CCFR-201b
Q1:
What is an advantage of using the IP Search tool?
○
A
IP searches provide manufacture and timezone data that can not be accessed anywhere else○
B
IP searches allow for multiple comma separated IPv6 addresses as input○
C
IP searches offer shortcuts to launch response actions and network containment on target hosts○
D
IP searches provide host, process, and organizational unit data without the need to write a query
CrowdStrike
CCFR-201b
Q2:
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
○
A
Filter on'Analyst: Alex'○
B
Alex does not have the correct role permissions as a Falcon Analyst to be assigned detections○
C
Filter on 'Hostname: Alex' and 'Status: In-Progress'○
D
Filter on 'Status: In-Progress' and 'Assigned-to: Alex*
CrowdStrike
CCFR-201b
Q3:
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in .CSV format?
○
A
You can't export detailed event data from a detection, you have to use the Process Timeline or an Event Search○
B
In Full Detection Details, you expand the nodes of the process tree you wish to expand and then click the 'Export Process Events' button○
C
In Full Detection Details, you choose the 'View Process Activity' option and then export from that view○
D
From the Detections Dashboard, you right-click the event type you wish to export and choose CSV. JSON or XML
CrowdStrike
CCFR-201b
Q4:
What is the difference between a Host Search and a Host Timeline?
○
A
Results from a Host Search return information in an organized view by type, while a Host Timeline returns a view of all events recorded by the sensor○
B
A Host Timeline only includes process execution events and user account activity○
C
Results from a Host Timeline include process executions and related events organized by data type. A Host Search returns a temporal view of all events for the given host○
D
There is no difference - Host Search and Host Timeline are different names for the same search page
CrowdStrike
CCFR-201b
Q5:
What happens when you open the full detection details?
○
A
The process explorer opens and the detection is removed from the console○
B
The process explorer opens and you're able to view the processes and process relationships○
C
The process explorer opens and the detection copies to the clipboard○
D
The process explorer opens and the Event Search query is run for the detection