Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFR-201b Exam - Topic 5 Question 8 Discussion

Actual exam question for CrowdStrike's CCFR-201b exam
Question #: 8
Topic #: 5
[All CCFR-201b Questions]

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Execution Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1.The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that loaded or executed those hashes1.You can also see a count of detections and incidents related to those hashes1.


Contribute your Thoughts:

0/2000 characters
Latonia
13 days ago
I thought it would be A, but B makes more sense.
upvoted 0 times
...
Lavonna
18 days ago
B is the right answer! It shows where those hashes were executed.
upvoted 0 times
...
Shawna
1 month ago
I thought we learned that the Hash Execution Search primarily focuses on hosts, so I'm leaning towards B as well.
upvoted 0 times
...
Merilyn
1 month ago
I feel like D could be a possibility too, but I can't recall if it specifically mentioned detections or just executions.
upvoted 0 times
...
Denise
1 month ago
I'm not entirely sure, but I remember a practice question that mentioned something about detecting processes related to hashes.
upvoted 0 times
...
Jesusita
2 months ago
I think the answer might be B, since it seems like it would show where those hashes were executed.
upvoted 0 times
...

Save Cancel