10 free sample questions from a bank of 90, with the correct answers and explanations. No signup required — start practising right now.
1Where can you find hosts that are in Reduced Functionality Mode?
Event Search
Executive Summary dashboard
Host Search
Installation Tokens
Answer: B
2What is an advantage of using a Process Timeline?
Process related events can be filtered to display specific event types
Suspicious processes are color-coded based on their frequency and legitimacy over time
Processes responsible for spikes in CPU performance are displayed over time
A visual representation of Parent-Child and Sibling process relationships is provided
Answer: A
3What action is used when you want to save a prevention hash for later use?
Always Block
Never Block
Always Allow
No Action
Answer: D
4You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?
IP Addresses
Remote or Network Logon Activity
Remote Access Graph
Hash Executions
Answer: A
5You are reviewing the raw data in an event search from a detection tree. You find a FileOpenInfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
ParentProcessId_decimal and aid
ResponsibleProcessId_decimal and aid
ContextProcessId_decimal and aid
TargetProcessId_decimal and aid
Answer: C
6How long are quarantined files stored in the CrowdStrike Cloud?
45 Days
90 Days
30 Days
Quarantined files are not deleted
Answer: B
7You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
Falcon X
Investigate
Discover
Spotlight
Answer: B
8What information is contained within a Process Timeline?
All cloudable process-related events within a given timeframe
All cloudable events for a specific host
Only detection process-related events within a given timeframe
A view of activities on Mac or Linux hosts
Answer: A
9Sensor Visibility Exclusion patterns are written in which syntax?
Glob Syntax
Kleene Star Syntax
RegEx
SPL (Splunk)
Answer: A
10In the "Full Detection Details", which view will provide an exportable text listing of events like DNS requests. Registry Operations, and Network Operations?