CCFR-201 CrowdStrike Certified Falcon Responder
Exam Independent Revision Guide and Practice
CROWDSTRIKE CCFR-201 FALCON RESPONDER EXAM – COMPLETE
Q&A BANK
200+ QUESTIONS WITH VERIFIED ANSWERS & DETAILED RATIONALES
SECTION 1: DETECTION ANALYSIS & INVESTIGATION (Questions 1-50)
1. A Falcon Responder is analyzing a detection where svchost.exe initiated an
outbound network connection to a known malicious IP address. The Process Tree
shows this svchost.exe instance has no parent process. Which investigative step
should be taken next within the Falcon UI to determine the root cause of this
suspicious activity? [citation:3]
A) Immediately isolate the host using Network Containment
B) Pivot to Process Explorer to investigate the process ancestry and command line
details
C) Create a blocklist rule for the IP address
D) Mark the detection as a false positive
1
,Answer: B
Rationale: When a critical system process like svchost.exe is exhibiting suspicious
behavior without a visible parent in the Process Tree, it suggests potential process
hollowing or injection. Process Explorer provides deeper visibility into process
ancestry, command lines, and child processes to uncover the root cause
[citation:3][citation:9].
2. During an investigation, you use the RTR command get
C:\Users\Public\artifact.exe. The command fails with an 'access denied' error, even
though you have administrative privileges. You suspect the file is locked by a
running process. Which sequence of RTR commands is the most effective way to
identify the locking process and successfully retrieve the file? [citation:3]
A) list C:\Users\Public\* → get C:\Users\Public\artifact.exe
B) ps → kill [PID] → get C:\Users\Public\artifact.exe
C) ps → run handle.exe -a artifact.exe → get C:\Users\Public\artifact.exe
D) run handle.exe -a artifact.exe → kill [PID] → get C:\Users\Public\artifact.exe
Answer: D
Rationale: First use handle.exe to identify the process locking the file, then kill the
identified PID to release the lock, then retrieve the file [citation:3].
3. A financial services firm has a legacy application that exhibits behavior similar
to credential dumping but is legitimate and required for quarterly reporting. This
generates false positive detections causing analyst fatigue. What is the most precise
method to suppress these specific detections without weakening security posture?
[citation:3]
2
,A) Create a blocklist rule for the application hash
B) Create an ML Exclusion for the specific file path and hash combination
C) Disable all detections for the host
D) Create a global allowlist for the process name
Answer: B
Rationale: ML Exclusions allow precise suppression of false positives using file
path and hash combination, maintaining security for the rest of the host
[citation:3].
4. When analyzing an executable with a global prevalence of "Common" but an
unknown executable name, what is the best course of action? [citation:10]
A) Ignore the detection as it is definitely benign
B) Immediately isolate the host
C) Click the VT Hash button to pivot to VirusTotal for more information
D) Create a blocklist rule for the hash
Answer: C
Rationale: Global Prevalence "Common" suggests widespread distribution and
likely benignity, but you should pivot to VirusTotal for confirmation
[citation:10][citation:9].
5. How does a DNSRequest event link to its responsible process? [citation:10]
3
, A) Through the ProcessName field
B) Through the ContextProcessId_decimal field
C) Through the ImageFileName field
D) Through the UserName field
Answer: B
Rationale: ContextProcessId_decimal contains the decimal process ID of the
process that generated the event, linking DNS query to its source process
[citation:10].
6. What happens when you create a Sensor Visibility Exclusion for a trusted file
path? [citation:10]
A) Files are still monitored but with lower priority
B) No events will be collected or sent to the CrowdStrike Cloud for that path
C) Only alerts are suppressed but logs are still collected
D) Files in that path are automatically blocked
Answer: B
Rationale: Sensor Visibility Exclusions prevent collection and transmission of
events for specified files or directories [citation:10].
4
Exam Independent Revision Guide and Practice
CROWDSTRIKE CCFR-201 FALCON RESPONDER EXAM – COMPLETE
Q&A BANK
200+ QUESTIONS WITH VERIFIED ANSWERS & DETAILED RATIONALES
SECTION 1: DETECTION ANALYSIS & INVESTIGATION (Questions 1-50)
1. A Falcon Responder is analyzing a detection where svchost.exe initiated an
outbound network connection to a known malicious IP address. The Process Tree
shows this svchost.exe instance has no parent process. Which investigative step
should be taken next within the Falcon UI to determine the root cause of this
suspicious activity? [citation:3]
A) Immediately isolate the host using Network Containment
B) Pivot to Process Explorer to investigate the process ancestry and command line
details
C) Create a blocklist rule for the IP address
D) Mark the detection as a false positive
1
,Answer: B
Rationale: When a critical system process like svchost.exe is exhibiting suspicious
behavior without a visible parent in the Process Tree, it suggests potential process
hollowing or injection. Process Explorer provides deeper visibility into process
ancestry, command lines, and child processes to uncover the root cause
[citation:3][citation:9].
2. During an investigation, you use the RTR command get
C:\Users\Public\artifact.exe. The command fails with an 'access denied' error, even
though you have administrative privileges. You suspect the file is locked by a
running process. Which sequence of RTR commands is the most effective way to
identify the locking process and successfully retrieve the file? [citation:3]
A) list C:\Users\Public\* → get C:\Users\Public\artifact.exe
B) ps → kill [PID] → get C:\Users\Public\artifact.exe
C) ps → run handle.exe -a artifact.exe → get C:\Users\Public\artifact.exe
D) run handle.exe -a artifact.exe → kill [PID] → get C:\Users\Public\artifact.exe
Answer: D
Rationale: First use handle.exe to identify the process locking the file, then kill the
identified PID to release the lock, then retrieve the file [citation:3].
3. A financial services firm has a legacy application that exhibits behavior similar
to credential dumping but is legitimate and required for quarterly reporting. This
generates false positive detections causing analyst fatigue. What is the most precise
method to suppress these specific detections without weakening security posture?
[citation:3]
2
,A) Create a blocklist rule for the application hash
B) Create an ML Exclusion for the specific file path and hash combination
C) Disable all detections for the host
D) Create a global allowlist for the process name
Answer: B
Rationale: ML Exclusions allow precise suppression of false positives using file
path and hash combination, maintaining security for the rest of the host
[citation:3].
4. When analyzing an executable with a global prevalence of "Common" but an
unknown executable name, what is the best course of action? [citation:10]
A) Ignore the detection as it is definitely benign
B) Immediately isolate the host
C) Click the VT Hash button to pivot to VirusTotal for more information
D) Create a blocklist rule for the hash
Answer: C
Rationale: Global Prevalence "Common" suggests widespread distribution and
likely benignity, but you should pivot to VirusTotal for confirmation
[citation:10][citation:9].
5. How does a DNSRequest event link to its responsible process? [citation:10]
3
, A) Through the ProcessName field
B) Through the ContextProcessId_decimal field
C) Through the ImageFileName field
D) Through the UserName field
Answer: B
Rationale: ContextProcessId_decimal contains the decimal process ID of the
process that generated the event, linking DNS query to its source process
[citation:10].
6. What happens when you create a Sensor Visibility Exclusion for a trusted file
path? [citation:10]
A) Files are still monitored but with lower priority
B) No events will be collected or sent to the CrowdStrike Cloud for that path
C) Only alerts are suppressed but logs are still collected
D) Files in that path are automatically blocked
Answer: B
Rationale: Sensor Visibility Exclusions prevent collection and transmission of
events for specified files or directories [citation:10].
4