CCFR-201 Exam QuestionsBrowse all questions from this exam

CCFR-201 Exam - Question 28


You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Show Answer
Correct Answer: B

Using the Hash Execution Search, one can determine which hosts have loaded or executed the specified SHA256 hashes. This is relevant because it helps in identifying the affected machines by looking up the hashes found in an intelligence report.

Discussion

10 comments
Sign in to comment
lightmagentaOption: B
Dec 12, 2023

answer is B

wildbandanaOption: B
Dec 14, 2023

Could also be the A

VasiOnCacaoOption: A
Dec 22, 2023

I actually think this is A. There is a lot more related here for process execution than hosts in the UI.

sbag0024Option: B
Jan 31, 2024

B is the answer. It even says on the page "Hosts that loaded/executed specified Hash"

kangaruOption: A
Feb 11, 2024

Both A and B are correct. But A shows more practical use case for Hash search.

mloboOption: A
Feb 19, 2024

Is A, totally

DkdnfnfmdkdkdOption: A
Mar 1, 2024

The correct answer is A

alanalanalanOption: A
May 21, 2024

Answer is A, the hash is refer to the process and it will usually use for IOC management for the process. compare A and B, A is asking "process" and B us asking "hosts loaded it", but A is better answer because "process execution" is before "host" and one host can be load the same process more than once.

alanalanalanOption: A
May 21, 2024

Answer is A, the hash is refer to the process and it will usually use for IOC management for the process. compare A and B, A is asking "process" and B us asking "hosts loaded it", but A is better answer because "process execution" is before "host" and one host can be load the same process more than once.

3ffa7f1Option: A
Jun 13, 2024

when you go to Hash Search you have a field Process Executions. I do not see anything related to Hosts. Answer is A