View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 81.
A Falcon Hunter identifies a suspicious process that launched from a user’s Downloads directory. Which action is most appropriate first?
- Review the process tree, command line, file hash, user context, and related network activity
2. Ignore the activity because Downloads is a normal folder
3. Delete all endpoint telemetry
4. Search only for the hostname
Correct Answer: 1
Explanation:
Execution from a Downloads directory can be legitimate, but it can also indicate user-delivered malware or recently downloaded tooling. The hunter should analyze the process tree, command line, hash, parent process, user, network activity, and any related file events. The location alone is not enough to classify the process. Combining multiple contextual signals helps determine whether the execution matches normal user behavior or represents suspicious activity.
Question 82.
Which behavior most strongly suggests possible persistence through service creation?
- A user launches a browser
2. A scheduled inventory task completes
3. A normal application update runs
4. An unfamiliar process creates a new service that launches an unknown executable at startup
Correct Answer: 4
Explanation:
Creating a new service that starts an unfamiliar executable can provide persistence because the program may automatically run during system startup. The hunter should inspect the service name, executable path, account, creation process, command line, and subsequent executions. Legitimate software installers may also create services, so rarity, timing, publisher information, and surrounding activity should be considered before determining whether the behavior is malicious.
Question 83.
Which telemetry is most useful when hunting for possible remote process execution across several hosts?
- Printer queues
2. Local display settings
3. Authentication events, process creation, source hosts, and destination hosts
4. Installed fonts
Correct Answer: 3
Explanation:
Remote process execution usually creates a combination of authentication and endpoint activity. The hunter should correlate the source system, destination system, account used, authentication time, and processes created remotely. This helps identify whether the activity is routine administration or possible lateral movement. Endpoint process telemetry provides important evidence because remote authentication alone does not show what happened after access was obtained.
Question 84.
Which approach is most effective when hunting for suspicious use of PowerShell across a large environment?
- Search only for the PowerShell executable name
2. Analyze command lines, parent processes, encoded content, users, and network activity
3. Treat every PowerShell execution as malicious
4. Ignore PowerShell because it is a legitimate utility
Correct Answer: 2
Explanation:
PowerShell is widely used for legitimate administration, so executable-name searches alone generate too much noise. Command-line arguments, encoded content, unusual parents, user context, download activity, and network connections provide stronger evidence. Behavioral analysis can identify suspicious use without blocking normal operations. Hunters should focus on how PowerShell is being used and whether the execution pattern deviates from expected administrative behavior.
Question 85.
A Falcon Hunter finds a rare executable that appears on several systems used by the same department. What is the best next step?
- Determine whether the executable is part of legitimate departmental software by reviewing its hash, path, signer, parent process, and behavior
2. Assume it is malicious because it is rare
3. Ignore it because multiple systems contain it
4. Delete all events related to the executable
Correct Answer: 1
Explanation:
Rare software can be legitimate, especially when deployed to a specific department or business function. The hunter should examine its signer, path, hash, parent process, command line, network behavior, and consistency across hosts. Business context can help determine whether the executable is expected. Rarity is useful for prioritization but should not be treated as proof of compromise without supporting evidence.
Question 86.
Which pattern is most consistent with possible command-and-control activity?
- A user opens an approved spreadsheet
2. A local backup completes normally
3. An application reads its configuration file
4. A suspicious process repeatedly connects to an uncommon external address at consistent intervals
Correct Answer: 4
Explanation:
Repeated outbound connections at regular intervals can indicate beaconing to command-and-control infrastructure. The hunter should examine the initiating process, destination, interval consistency, DNS activity, affected hosts, and traffic volume. Legitimate software can also communicate periodically, so baselining is important. Correlation with suspicious process execution, persistence, or user activity can increase confidence that the behavior is malicious.
Question 87.
Which activity is most relevant when investigating possible credential-access behavior?
- A normal browser launch
2. A routine file copy
3. An unexpected process interacting with credential-related memory or authentication components
4. A user changing screen resolution
Correct Answer: 3
Explanation:
Credential-access activity may involve processes reading sensitive memory, files, registries, or authentication-related components. The hunter should determine which process performed the access, the privilege level, parent process, account involved, and whether unusual logons followed. This can reveal whether credentials were subsequently used for privilege escalation or lateral movement. Legitimate security or administrative tools should be evaluated in context.
Question 88.
Which statement best describes why hunters use aggregation during large event searches?
- Aggregation proves all matching events are malicious.
2. Aggregation helps summarize frequency and identify patterns or outliers across large data sets.
3. Aggregation removes the need for detailed investigation.
4. Aggregation is used only for host inventory.
Correct Answer: 2
Explanation:
Aggregation can group large event sets by fields such as host, user, process, command line, or destination. This helps hunters quickly identify unusual concentrations, rare values, or common patterns. Once an interesting pattern is found, individual events can be reviewed for deeper context. Aggregation is therefore a triage and analysis technique, not a substitute for event-level validation.
Question 89.
A hunter detects an Office application spawning a scripting engine followed by an outbound connection. What is the best investigative interpretation?
- The sequence may indicate malicious document execution and should be investigated further.
2. The behavior is always normal for Office applications.
3. The network connection proves the user is malicious.
4. Parent-child relationships should be ignored.
Correct Answer: 1
Explanation:
An Office application launching a scripting engine and then generating outbound communication can be associated with malicious documents, macros, or exploitation. The hunter should review the document origin, process tree, command line, child processes, downloaded files, and destination. The sequence is suspicious but not conclusive because legitimate automation may occasionally produce similar behavior. Context and recurrence across hosts are important.
Question 90.
Which behavior is most suspicious during a hunt for data exfiltration?
- A user opens a local document
2. A scheduled patch installs
3. A normal application checks for updates
4. A rare process reads many sensitive files and then transfers a large volume of data externally
Correct Answer: 4
Explanation:
A process that accesses large numbers of sensitive files and then sends a significant amount of data externally presents a strong exfiltration hypothesis. The hunter should inspect which files were accessed, the responsible process, user context, destination, timing, and whether compression or staging occurred beforehand. Legitimate synchronization or backup software can create similar patterns, so the activity should be compared against baseline behavior.
Question 91.
Which technique is most effective for finding malicious behavior when adversaries frequently change their tools’ filenames?
- Search only filenames
2. Search only known IP addresses
3. Hunt on behavioral patterns such as process ancestry, command lines, and event sequences
4. Ignore endpoint telemetry
Correct Answer: 3
Explanation:
Filenames are easy for attackers to change. Behavioral patterns such as unusual process relationships, command-line syntax, network activity, and persistence mechanisms often remain more consistent. Behavioral hunting therefore provides more durable detection than relying solely on filenames or other static indicators. Static indicators still have value, but they are most effective when combined with behavioral context.
Question 92.
Which statement best describes the purpose of a hunting baseline?
- It marks all uncommon activity as malicious.
2. It defines expected behavior so unusual deviations can be prioritized for investigation.
3. It guarantees zero false positives.
4. It eliminates the need for threat intelligence.
Correct Answer: 2
Explanation:
Baselines provide a reference for what is normal for a host, process, account, or environment. Hunters can then identify meaningful deviations, such as a service account logging into a new system or a process contacting an unusual destination. Uncommon behavior is not automatically malicious, so contextual analysis remains necessary. Baselines help prioritize attention in large environments where reviewing every event individually is impractical.
Question 93.
A hunter sees the same account authenticate to several servers that the user does not normally access. What should the hunter investigate first?
- Source host, authentication method, destination systems, and resulting activity
2. Only the account display name
3. Printer activity
4. Wallpaper settings
Correct Answer: 1
Explanation:
Unexpected authentication to multiple servers may indicate lateral movement, credential compromise, or legitimate administrative activity. The hunter should determine where the authentication originated, how it occurred, which servers were reached, and what processes or actions followed. User role and historical behavior provide important context. Authentication success alone does not prove that the activity was authorized.
Question 94.
Which activity most strongly suggests defense evasion?
- A user opens a browser
2. A normal application update occurs
3. A scheduled security scan completes
4. A process modifies security exclusions and then removes its execution artifacts
Correct Answer: 4
Explanation:
Changing security exclusions can reduce detection coverage, while deleting execution artifacts can hinder forensic investigation. The combination of these behaviors is strongly suspicious and should be investigated promptly. The hunter should identify the responsible process, user, parent process, command line, affected security controls, and subsequent activity. Multiple defense-evasion actions together provide stronger evidence than one isolated event.
Question 95.
Which approach is most effective after identifying a suspicious external domain on one endpoint?
- Ignore the process that contacted the domain
2. Search only the domain reputation
3. Search enterprise telemetry for associated hosts, processes, users, and timestamps
4. Delete the original network event
Correct Answer: 3
Explanation:
Enterprise-wide searching helps determine whether the suspicious domain is associated with one host or broader activity. The hunter should identify which processes made connections, which users were active, and when the connections occurred. This can reveal common execution patterns or multiple compromised systems. External reputation can provide useful context, but local telemetry is necessary to understand the domain’s role in the environment.
Question 96.
Which statement best describes the role of threat intelligence in a hunting workflow?
- Threat intelligence should replace endpoint telemetry.
2. Threat intelligence can help develop hypotheses and prioritize behaviors or indicators for investigation.
3. Threat intelligence proves every matching indicator is malicious.
4. Threat intelligence is useful only after an incident is closed.
Correct Answer: 2
Explanation:
Threat intelligence can provide context about adversary techniques, infrastructure, campaigns, and observed behaviors. Hunters can use this information to formulate hypotheses and prioritize searches. However, a match to an intelligence indicator should still be validated against local telemetry because infrastructure can be shared or outdated. Threat intelligence is most useful when combined with behavioral and environmental context.
Question 97.
A hunter identifies an unusual remote administration tool on a user’s workstation. What is the best next action?
- Review the tool’s execution history, user, source, destinations, command line, and related network activity
2. Assume the tool is malicious solely because it is rare
3. Ignore it because remote administration tools are legitimate software
4. Delete all host logs
Correct Answer: 1
Explanation:
Remote administration tools can be used legitimately or abused by attackers. The hunter should determine who installed or executed the tool, when it first appeared, which systems it contacted, and whether its use aligns with the user’s role. Rare or unauthorized tools deserve scrutiny, but context is necessary before concluding maliciousness. Behavioral evidence is especially important when the binary itself is legitimate.
Question 98.
Which behavior most strongly suggests possible privilege escalation?
- A user opens an approved application
2. A standard inventory task runs
3. A normal browser session begins
4. A low-privilege process unexpectedly launches code with elevated permissions
Correct Answer: 4
Explanation:
An unexpected change from low privilege to elevated execution can indicate exploitation, token manipulation, abuse of a privileged service, or another escalation technique. The hunter should inspect the process ancestry, user context, command line, elevation mechanism, and subsequent privileged activity. Legitimate installers and administrative workflows can also elevate processes, so the surrounding context must be reviewed.
Question 99.
Which investigation method is most useful for reconstructing the order of attacker actions on a compromised endpoint?
- Reviewing only detection names
2. Searching only the username
3. Building a timeline of process, file, network, and authentication events
4. Reviewing only installed applications
Correct Answer: 3
Explanation:
A timeline helps the hunter understand the sequence of events and relationships between activities. It can reveal initial execution, persistence, credential access, network communication, and other follow-on behavior. Temporal context is often essential for distinguishing cause from coincidence. Timelining also helps identify what occurred immediately before and after a detection and can expose previously unnoticed stages of an intrusion.
Question 100.
Which action best completes a productive threat hunt after malicious activity has been validated?
- Delete investigation notes
2. Document findings, scope affected systems, support response, and turn useful hunting logic into future detections where appropriate
3. Disable relevant telemetry
4. Leave the hunt undocumented
Correct Answer: 2
Explanation:
A successful threat hunt should improve both immediate incident response and future detection capability. Hunters should document evidence, affected systems, timelines, users, indicators, and behavioral findings. Confirmed malicious activity should be handed off or coordinated with response teams. Useful queries or behavioral patterns may also become reusable detections, helping the organization identify similar activity faster in the future.
\