View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 1.
A Falcon Hunter begins investigating a detection involving a suspicious PowerShell process. What should the hunter do first to establish the process context?
- Review the process tree, parent and child processes, command line, user, and host activity
2. Immediately delete the process from the host
3. Disable all detections for PowerShell
4. Search only for the executable file name
Correct Answer: 1
Explanation:
A process tree provides important context for determining how a suspicious process started, what launched it, what it launched afterward, and which user or host was involved. Command-line details can reveal encoded commands, downloads, or suspicious parameters. A hunter should build context before drawing conclusions or taking disruptive action. Searching only for the executable name may produce many legitimate results because PowerShell is commonly used for administration. CrowdStrike’s current CCFH scope emphasizes detection analysis, investigation tools, event searching, and hunting methodology.
Question 2.
A hunter wants to understand activity that occurred before and after a suspicious process execution on one endpoint. Which investigation approach is most appropriate?
- Review only the detection name
2. Search only for the hostname
3. Export the user list
4. Build a timeline of related endpoint events around the suspicious process
Correct Answer: 4
Explanation:
A timeline helps reconstruct activity surrounding a suspicious event and can reveal process creation, network connections, file operations, user activity, and related behavior before and after the detection. This is particularly useful when determining whether a detection represents an isolated event or part of a larger attack sequence. Looking only at the detection name or hostname provides insufficient behavioral context. The CCFH role specifically focuses on deeper detection analysis, machine timelining, and event-related investigations.
Question 3.
Which framework is most useful when a Falcon Hunter wants to categorize observed adversary behavior by tactics and techniques?
- COBIT
2. ITIL
3. MITRE ATT&CK
4. PCI DSS
Correct Answer: 3
Explanation:
MITRE ATT&CK provides a structured framework for describing adversary tactics, techniques, and sub-techniques. Hunters can use it to categorize observed behavior, identify likely follow-on activity, and organize hunting hypotheses. For example, suspicious credential access may lead the hunter to investigate lateral movement or persistence techniques. The current CrowdStrike CCFH exam guide explicitly lists MITRE ATT&CK frameworks as one of the exam-scope topics.
Question 4.
A Falcon Hunter wants to find all events associated with a specific suspicious process identifier on a host. Which capability should be used?
- Sensor uninstall
2. Event search using the relevant process and host fields
3. Host containment only
4. User provisioning
Correct Answer: 2
Explanation:
Event search enables a hunter to pivot from a known artifact, such as a process identifier, host, user, hash, IP address, or other event field, to related telemetry. This allows the investigator to understand the broader activity surrounding a process instead of relying solely on the initial detection. Host containment may be appropriate during response, but it does not replace investigation. CrowdStrike identifies Event Search as a core area of the CCFH exam.
Question 5.
A detection shows a command shell launched by a Microsoft Office application. Why is this parent-child relationship significant?
- Office applications normally should not launch command shells during ordinary document viewing
2. Every Office process launches a command shell by design
3. The relationship proves the host is clean
4. Parent-child relationships are irrelevant during threat hunting
Correct Answer: 1
Explanation:
Unusual parent-child relationships are valuable hunting indicators because attackers frequently abuse trusted applications to launch scripts, interpreters, or command shells. An Office application spawning a shell may indicate malicious document execution, exploitation, or user-enabled content. The hunter should examine the command line, subsequent processes, network connections, files created, and related user activity. The relationship alone does not prove maliciousness, but it provides a strong hypothesis for deeper investigation.
Question 6.
Which activity is most useful when developing a proactive threat-hunting hypothesis?
- Randomly opening detections without a goal
2. Reviewing printer configuration
3. Ignoring threat intelligence
4. Starting with an adversary behavior, risk condition, or observable pattern that can be tested against telemetry
Correct Answer: 4
Explanation:
A hunting hypothesis should be testable and based on a realistic attacker behavior, threat intelligence finding, environment-specific risk, or observable anomaly. For example, a hunter might hypothesize that attackers are using scripting interpreters to download payloads from rare domains. The hunter can then identify relevant telemetry and construct queries to validate or reject the hypothesis. This structured process is more effective than searching events without a defined objective. Hunting methodology is explicitly included in the CCFH exam scope.
Question 7.
A hunter finds a suspicious executable hash on one endpoint and wants to determine whether it appeared elsewhere in the environment. What should the hunter do?
- Search only the original endpoint
2. Ignore the hash because file hashes cannot be hunted
3. Search enterprise telemetry for the hash across hosts and relevant events
4. Immediately reinstall every endpoint
Correct Answer: 3
Explanation:
Searching for the hash across enterprise telemetry helps determine whether the suspicious file is isolated or widespread. The hunter can then identify affected hosts, users, execution times, parent processes, and associated network activity. This type of pivoting is fundamental to investigation because a single detection may represent only one visible part of a larger intrusion. Hash searches should be combined with behavioral analysis because adversaries may modify files to change their hashes.
Question 8.
A hunter needs to determine whether a suspicious domain was contacted by multiple hosts. Which approach is most appropriate?
- Review only file-write events
2. Search network or DNS-related telemetry for the domain and summarize affected hosts
3. Disable DNS on all endpoints
4. Search only for usernames
Correct Answer: 2
Explanation:
Searching network and DNS-related telemetry for a suspicious domain allows the hunter to identify which endpoints contacted it, when communication occurred, and which processes were responsible. Summarizing results by host can reveal whether the activity is isolated or widespread. Domain searches are a common investigation pivot within Falcon hunting workflows. CrowdStrike’s CCFH guidance specifically references IP and domain searches as part of investigative activity.
Question 9.
A hunter observes the same suspicious command line on several endpoints. What is the best next step?
- Determine the common user, parent process, deployment mechanism, and related events across the affected hosts
2. Assume the behavior is benign because it appears on multiple systems
3. Delete all endpoint telemetry
4. Ignore the command line and investigate only filenames
Correct Answer: 1
Explanation:
Repeated suspicious command lines across multiple hosts may indicate automated attacker activity, lateral movement, malicious software deployment, or a legitimate administrative tool. The hunter should identify common characteristics such as users, parent processes, hosts, timing, network destinations, and execution mechanisms. These relationships can reveal the scope and source of activity. Repetition does not automatically make behavior benign; in some incidents, widespread execution is precisely what indicates coordinated compromise.
Question 10.
Which event characteristic is most useful when reconstructing relationships between processes during a Falcon investigation?
- Screen resolution
2. Printer name
3. Keyboard layout only
4. Process identifiers and parent-child relationships
Correct Answer: 4
Explanation:
Process identifiers and parent-child relationships help hunters reconstruct execution chains and understand how activity developed. An investigator can identify the original process, what launched it, and which child processes followed. This context is essential for differentiating legitimate application behavior from malicious process chains. Other contextual fields such as timestamps, user identity, command line, file hashes, and host information can strengthen the investigation.
Question 11.
A Falcon detection references credential-access behavior. Which investigation step is most appropriate?
- Review only the host’s operating system version
2. Ignore subsequent authentication activity
3. Examine related processes, targeted credential stores, user activity, and subsequent logons or lateral movement
4. Delete all authentication logs
Correct Answer: 3
Explanation:
Credential-access activity can enable attackers to escalate privileges or move to other systems. The hunter should examine the process responsible, what credential-related resources it accessed, which user context was involved, and whether unusual authentication or lateral movement followed. Mapping the activity to relevant ATT&CK techniques can help identify likely next steps. The investigation should preserve authentication evidence rather than remove it.
Question 12.
Which statement best describes the value of aggregating event-search results during threat hunting?
- Aggregation hides all meaningful activity.
2. Aggregation can reveal frequency, concentration, and patterns across hosts, users, processes, or other fields.
3. Aggregation is useful only for licensing.
4. Aggregation eliminates the need to review individual events.
Correct Answer: 2
Explanation:
Aggregation helps a hunter move from individual events to patterns. For example, grouping suspicious activity by hostname may reveal the most affected systems, while grouping by process or user can identify common execution paths or identities. This can make large event sets easier to interpret and help prioritize deeper investigation. Aggregated results should still be validated against underlying events when precise context is required.
Question 13.
A hunter wants to investigate whether a suspicious executable was renamed before execution. Which combination of evidence would be most useful?
- File hash, process path, file name, and execution events
2. Screen brightness and audio settings
3. Only the visible file name
4. Only the user’s department
Correct Answer: 1
Explanation:
Attackers may rename malicious or legitimate tools to avoid simple filename-based detections. Comparing the file hash with the observed name, path, process execution, and related event data can reveal inconsistencies. A known tool executing under an unexpected name or directory can be suspicious. Hashes are not sufficient by themselves because files can be modified, so the hunter should combine file identity with behavioral context.
Question 14.
Which investigation approach best helps determine whether a suspicious IP address represents command-and-control activity?
- Search only for the IP in printed reports.
2. Ignore which process made the connection.
3. Assume every external IP is malicious.
4. Correlate the IP with endpoint connections, initiating processes, hosts, timing, and related activity.
Correct Answer: 4
Explanation:
An IP address alone rarely provides enough context to determine intent. The hunter should identify which hosts communicated with it, which processes initiated the connections, when communication occurred, and whether other suspicious behavior accompanied it. Threat intelligence may provide additional context, but local telemetry remains important. Correlation helps distinguish malicious command-and-control traffic from legitimate cloud infrastructure or shared services.
Question 15.
A threat hunter wants to search for endpoints where a scripting interpreter launched a network utility shortly afterward. What type of hunting technique is this?
- Asset depreciation
2. Vulnerability patch scheduling
3. Behavioral sequence hunting
4. License management
Correct Answer: 3
Explanation:
Behavioral sequence hunting looks for combinations or chains of events that may represent attacker behavior rather than relying on a single indicator. A scripting interpreter launching a network utility may be legitimate in some environments, but when combined with unusual command lines, users, destinations, or parent processes, it can become a valuable hunting lead. Sequence-oriented hunting is useful for identifying adversary tradecraft that changes filenames or hashes while preserving behavioral patterns.
Question 16.
Which statement best describes the purpose of reports and references during a Falcon hunting workflow?
- They replace all raw-event investigation.
2. They can provide summarized context and reusable information that helps prioritize or guide deeper hunting.
3. They are used only for sensor installation.
4. They prevent hunters from creating custom queries.
Correct Answer: 2
Explanation:
Reports and reference information can summarize relevant telemetry, recurring patterns, assets, or known investigative context. They can help hunters identify areas worth deeper investigation and reduce repeated manual analysis. However, reports do not eliminate the need to inspect underlying event data when validating a hypothesis. CrowdStrike includes Reports and References as a specific topic in the current CCFH exam scope. CrowdStrike.com
Question 17.
Which approach best helps a Falcon Hunter distinguish a legitimate administrative utility from malicious use of the same utility?
- Evaluate command line, parent process, user, host, timing, destination, and surrounding behavior
2. Mark every administrative tool as malicious
3. Ignore command-line arguments
4. Base the decision only on the executable’s digital signature
Correct Answer: 1
Explanation:
Many attacker techniques rely on legitimate tools already present in the environment. The executable itself may therefore be trusted even when its use is malicious. Hunters should evaluate behavior and context, including who launched the utility, how it was started, what arguments were supplied, what systems it contacted, and what occurred before and afterward. This helps distinguish ordinary administration from living-off-the-land activity.
Question 18.
Which activity is most suspicious during a hunt for defense-evasion behavior?
- An approved application performs its normal update.
2. A user opens a routine business document.
3. A scheduled inventory scan completes.
4. A process disables endpoint security controls immediately before launching an unknown executable.
Correct Answer: 4
Explanation:
Disabling security controls immediately before launching an unknown executable is strongly suspicious because adversaries frequently attempt to weaken defenses before executing malware or other tooling. The hunter should examine the responsible process, user context, parent process, command line, subsequent execution, and related host activity. Mapping the behavior to MITRE ATT&CK can also help identify associated defense-evasion techniques and likely follow-on behavior.
Question 19.
A hunter finds a suspicious process on one endpoint. Which action best helps determine the full enterprise scope of the activity?
- Investigate only the original detection.
2. Contain the host and stop all further analysis.
3. Pivot on relevant indicators and behaviors across enterprise telemetry to identify related hosts, users, processes, and connections.
4. Delete the detection after reviewing the process name.
Correct Answer: 3
Explanation:
Enterprise scoping requires pivoting from the initial event to related indicators and behaviors across the environment. Useful pivots can include hashes, process names, command lines, IP addresses, domains, usernames, and execution patterns. This may reveal additional affected hosts or related stages of the intrusion. Containment may be necessary during response, but hunting should still establish scope so hidden activity is not overlooked.
Question 20.
Which approach best represents an effective threat-hunting methodology?
- Search randomly until something unusual appears.
2. Define a hypothesis, identify required telemetry, query and analyze the data, validate findings, and refine the hunt.
3. Investigate only alerts that have already been confirmed malicious.
4. Avoid documenting findings so future hunts remain independent.
Correct Answer: 2
Explanation:
Effective threat hunting is structured and repeatable. A hunter begins with a hypothesis based on adversary behavior, intelligence, detection gaps, or organizational risk. The hunter identifies the telemetry required, constructs searches, analyzes results, validates suspicious findings, and refines the hypothesis as new evidence emerges. Findings can then improve future detections and hunting analytics. CrowdStrike lists Hunting Analytics and Hunting Methodology among the current CCFH exam-scope areas.