100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CCFR Exam Study Guide Questions & Answers 2024/2025 $9.49   Add to cart

Exam (elaborations)

CCFR Exam Study Guide Questions & Answers 2024/2025

 0 view  0 purchase
  • Course
  • CCFR
  • Institution
  • CCFR

CCFR Exam Study Guide Questions & Answers 2024/2025 Timelines are part of which Falcon page? - ANSWERSInvestigate Where can you find information about Detection and Prevention Policies? - ANSWERSIn the Support page under Docs A scheduled task being executed causes a detection. How is thi...

[Show more]

Preview 2 out of 15  pages

  • November 25, 2024
  • 15
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • CCFR
  • CCFR
avatar-seller
Bensuda
CCFR Exam Study Guide Questions &
Answers 2024/2025

Timelines are part of which Falcon page? - ANSWERSInvestigate



Where can you find information about Detection and Prevention Policies? - ANSWERSIn the Support
page under Docs



A scheduled task being executed causes a detection. How is this revealed in the process tree? -
ANSWERSThe process tree begins with TASKENG.EXE



What are filters available in the drop down menu on the Detections page? - ANSWERSCommand line,
Status, Hash



Which detection type is NOT automated? - ANSWERSFalcon Overwatch



What are the different types of detections the Falcon Sensor use? - ANSWERSAutomated, Manual,
Custom



ProcessRollup2 refers to a(n) ____ field - ANSWERSevent_simpleName



Within the MITRE Framework, what would Gain Access -> Initial Access -> Drive-by Compromise mean? -
ANSWERSAn adversary is trying to gain access by initial access using drive-by compromise



Which of the following is an example of a MITRE ATT&CK technique - ANSWERSProcess Injection



During you investigation of a detection, you discover that the triggering file was launched from
TASKENG.EXE. What does this mean? - ANSWERSThe triggering file is part of a scheduled task being
executed.

, Which search is not available as a pivot from a detection? - ANSWERSUser search



What type of events are shown in a Process Timeline? - ANSWERSAll cloudable process-related events in
a given timeframe



Which dashboard will show endpoints in RFM? - ANSWERSExecutive Summary



How does a NetworkConnectIP4 event link to its responsible process? - ANSWERSVia its
ContextProcessId_decimal field



What is an "Unmanaged Neighbor" found in Host search? - ANSWERSA local endpoint that does not have
a sensor installed



What happens when a file is quarantined? - ANSWERSIt is compressed, password protected, and moved
to the Quarantine folder on the endpoint. It is also deleted after 30 days.



What does the "Objective" layer do as it relates to the MITRE ATT&CK Framework? - ANSWERSGroups
related MITRE tactics together to make them easier to learn and remember.



What are the Objectives that exist in the Falcon UI? - ANSWERSGain access, Keep access, Explore,
Contact controlled systems, Follow through, Network-based effects



What MITRE tactics are covered by the Gain Access objective? - ANSWERSInitial Access, Credential
Access, Privilege Escalation



What MITRE tactics are covered by the Keep access objective? - ANSWERSPersistence, Defense Evasion



What MITRE tactics are covered by the Explore objective? - ANSWERSDiscovery, Lateral Movement



What MITRE tactics are covered by the Contact controlled systems objective? - ANSWERSCommand and
Control

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Bensuda. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $9.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

67096 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$9.49
  • (0)
  Add to cart