Official Bank 0/60

CrowdStrike Certified Falcon Responder (CCFR-201) - CrowdStrike Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
60 Total Questions
1
Question
Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?
Options
A Credential Access via OS Credential Dumping
B Malware via PUP
C Machine Learning via Cloud-Based ML
D Falcon Intel via Intelligence Indicator - Domain
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
How long does detection data remain in the CrowdStrike Cloud before purging begins?
Options
A 30 Days
B 45 Days
C 14 Days
D 90 Days
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
What happens when a hash is set to Always Block through IOC Management?
Options
A The hash is submitted for approval to be blocked from execution once confirmed by Falcon specialists
B Execution is prevented on selected host groups
C Execution is prevented and detection alerts are suppressed
D Execution is prevented on all hosts by default
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
The Bulk Domain Search tool contains Domain information along with which of the following?
Options
A IP Lookup Information
B Port Information
C Threat Actor Information
D Process Information
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
How long are quarantined files stored on the host?
Options
A Quarantined files are never deleted from the host
B 90 Days
C 30 Days
D 45 Days
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.