| Exam Code/Number: | CCFR-201bJoin the discussion |
| Exam Name: | CrowdStrike Certified Falcon Responder |
| Certification: | CrowdStrike |
| Question Number: | 184 |
| Publish Date: | May 31, 2026 |
|
Rating
100%
|
|
An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?