CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part8 Q141-160

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 141.

A Falcon Hunter notices a newly created process executing from a user profile directory and making outbound connections shortly afterward. What should be investigated first?

  1. The process ancestry, file hash, command line, user context, and network destinations
    2. The user’s printer history
    3. Only the executable filename
    4. The endpoint’s display settings

Correct Answer: 1

Explanation:

Execution from a user profile directory can be legitimate, but it is also commonly associated with downloaded or user-level malware. The hunter should examine the parent process, command line, hash, path, user, and outbound connections to understand how the executable arrived and what it did. A filename alone is easy to change and provides limited context. Correlating process and network behavior helps determine whether the activity represents legitimate software or suspicious execution.

Question 142.

Which behavior most strongly suggests persistence through startup configuration?

  1. A user launches an approved browser
    2. A normal software update runs
    3. A document is saved locally
    4. An unknown executable is configured to launch automatically when the user signs in

Correct Answer: 4

Explanation:

Configuring an unknown executable to start automatically at user logon can provide persistence across sessions. The hunter should identify which process created the startup entry, which account was involved, where the executable resides, and whether similar entries exist on other hosts. Legitimate applications may also configure startup behavior, so rarity, signer information, timing, and surrounding activity should be reviewed before concluding that the behavior is malicious.

Question 143.

Which telemetry is most useful for investigating suspected lateral movement through administrative shares?

  1. Local wallpaper settings
    2. Printer configuration
    3. Source and destination hosts, authentication activity, share access, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Administrative-share activity is most meaningful when correlated with the account used, originating host, destination system, timestamps, and any process execution that followed. This combination can help distinguish normal systems administration from adversary movement. Reviewing only one event type may miss the complete sequence. Hunters should also compare the activity against the user’s normal role and historical behavior to determine whether the access is expected.

Question 144.

Which approach is most effective when a hunter suspects malicious use of a trusted scripting engine?

  1. Treat all scripting activity as malicious
    2. Examine command lines, parent-child relationships, users, network activity, and resulting files
    3. Ignore the activity because the interpreter is signed
    4. Search only for the interpreter’s executable name

Correct Answer: 2

Explanation:

Trusted scripting engines are commonly used for both legitimate administration and attacker tradecraft. The hunter should focus on how the interpreter was invoked, what commands or scripts it executed, which process launched it, what files were created, and which network destinations were contacted. Signed software can still be abused. Contextual behavioral analysis is therefore more useful than classifying the interpreter itself as either safe or malicious.

Question 145.

A Falcon Hunter identifies a process that appears on only two hosts and has never been seen before. What is the best next step?

  1. Review the process path, signer, hash, command line, ancestry, and associated activity
    2. Automatically classify it as malicious because it is rare
    3. Ignore it because only two hosts are affected
    4. Delete all events involving the process

Correct Answer: 1

Explanation:

Rarity can help prioritize a process for investigation, but it does not prove maliciousness. New software, department-specific utilities, and legitimate custom applications can also be rare. The hunter should evaluate the process’s signer, path, hash, parent, command line, user, and network activity. The combination of rarity and suspicious behavior provides a much stronger signal than rarity alone.

Question 146.

Which pattern is most consistent with command-and-control beaconing?

  1. A user opens a local spreadsheet
    2. A scheduled inventory scan runs
    3. A normal application reads a configuration file
    4. A process repeatedly connects to the same rare destination at nearly regular intervals

Correct Answer: 4

Explanation:

Periodic outbound connections to an uncommon destination can indicate beaconing behavior used by command-and-control frameworks. The hunter should inspect the initiating process, destination, interval regularity, affected hosts, and related DNS activity. Legitimate applications can also produce periodic traffic, so baseline behavior and business context are important. Beaconing becomes more suspicious when paired with unusual execution, persistence, or credential-access behavior.

Question 147.

Which event pattern is most relevant when hunting for credential access?

  1. A user opens an approved application
    2. A normal file is copied locally
    3. An unexpected process interacts with credential stores or authentication-related memory
    4. A printer job completes

Correct Answer: 3

Explanation:

Credential-access techniques often involve processes interacting with sensitive memory, registry locations, files, or authentication components. The hunter should identify the responsible process, privilege level, parent process, and account context. Subsequent unusual authentications or remote activity may indicate that credentials were successfully obtained and reused. Legitimate security software can perform similar operations, so the full execution context must be considered.

Question 148.

Which statement best describes the purpose of grouping search results by parent process?

  1. It proves every child process from a rare parent is malicious.
    2. It can reveal unusual execution relationships and recurring process chains.
    3. It replaces the need to inspect command lines.
    4. It is useful only for software inventory.

Correct Answer: 2

Explanation:

Grouping by parent process can expose unusual execution relationships that might otherwise be hidden in large result sets. For example, a scripting engine launched by an uncommon parent may stand out when compared with normal activity. Hunters can then drill into command lines, child processes, users, and network events for validation. Aggregation helps prioritize investigation but should not be treated as proof of maliciousness.

Question 149.

A hunter observes a spreadsheet application spawning a command interpreter, which then downloads an executable. What is the best next step?

  1. Investigate the document source, process chain, command line, downloaded file, and network destination
    2. Assume the sequence is normal office behavior
    3. Ignore the interpreter because it is built into the operating system
    4. Delete the detection immediately

Correct Answer: 1

Explanation:

A spreadsheet application spawning a command interpreter followed by a file download is a suspicious sequence that can indicate malicious document execution. The hunter should inspect the original document, process ancestry, command-line arguments, downloaded file hash, destination, and subsequent execution. The behavior is not automatically malicious, but the combination of process relationships and network activity provides a strong hunting lead.

Question 150.

Which behavior most strongly suggests data staging?

  1. A standard application writes a small log file
    2. A user opens a web browser
    3. A routine patch installs
    4. A process gathers documents from several folders and compresses them into a large archive

Correct Answer: 4

Explanation:

Attackers may stage data by collecting and compressing files before exfiltration. A large archive built from multiple directories can therefore be a meaningful hunting signal, particularly when followed by unusual outbound traffic. The hunter should inspect the files collected, process responsible, user context, destination path, and any subsequent network transfers. Legitimate backup or archiving activity should also be considered during validation.

Question 151.

Which hunting technique is most useful when an attacker changes hashes and filenames frequently but continues using similar execution chains?

  1. Exact hash matching only
    2. Filename searches only
    3. Behavioral hunting based on process ancestry, command lines, and event sequences
    4. Ignoring process telemetry

Correct Answer: 3

Explanation:

Behavioral hunting is more resilient than static indicators when adversaries frequently change binaries, names, or infrastructure. Process ancestry, command-line syntax, persistence methods, and event sequences often remain recognizable across multiple tool variants. Hashes and filenames are still useful for quick scoping, but behavioral patterns provide broader coverage when attackers deliberately modify superficial indicators.

Question 152.

Which statement best describes the value of baselining process activity?

  1. It proves that common processes are always safe.
    2. It helps identify process behavior that deviates from what is normally observed in the environment.
    3. It removes the need for human investigation.
    4. It automatically blocks all rare processes.

Correct Answer: 2

Explanation:

Process baselines help hunters understand which executables, parents, paths, and command lines are commonly seen on specific systems or user groups. Deviations can then be prioritized for review. A common process can still be abused, and a rare process can be legitimate, so baseline information must be combined with context. The goal is to focus attention on meaningful anomalies rather than classify activity automatically.

Question 153.

A user account suddenly authenticates from one workstation to multiple servers within a few minutes. What should be investigated first?

  1. The source host, account, authentication method, destination systems, and resulting processes
    2. Only the user’s display name
    3. The endpoint’s printer configuration
    4. Screen brightness settings

Correct Answer: 1

Explanation:

Rapid authentication to multiple servers can represent legitimate administration or lateral movement. The hunter should identify where the activity originated, which authentication method was used, which systems were accessed, and what processes or actions followed. Historical user behavior and job role provide important context. A sequence of unusual logons followed by remote execution would increase concern.

Question 154.

Which activity most strongly suggests defense evasion?

  1. A normal application starts
    2. A scheduled update completes
    3. A routine inventory scan runs
    4. A process disables security services, changes exclusions, and clears logs

Correct Answer: 4

Explanation:

The combination of disabling security services, modifying exclusions, and clearing logs strongly suggests an attempt to reduce visibility and avoid detection. The hunter should examine the responsible process, user, parent process, commands executed, and subsequent activity. Multiple defense-evasion behaviors occurring together are generally more significant than a single isolated event. Remaining telemetry should be preserved for deeper investigation.

Question 155.

A suspicious domain appears in endpoint telemetry. Which action best helps determine its scope?

  1. Review only its external reputation
    2. Ignore which processes contacted it
    3. Search enterprise telemetry for associated hosts, processes, users, and timestamps
    4. Delete the original event

Correct Answer: 3

Explanation:

Searching for the domain across the environment reveals how widely it appears and which processes or users are associated with the connections. This can expose additional affected systems or recurring behavior. Reputation data is useful context but cannot replace local telemetry. A domain may be shared by legitimate and malicious services, so understanding how it was used inside the environment is essential.

Question 156.

Which statement best describes how threat intelligence should be used in threat hunting?

  1. It should replace endpoint telemetry.
    2. It can help prioritize adversary behaviors, indicators, and hypotheses that should be tested against local data.
    3. Every intelligence match should be considered confirmed compromise.
    4. It is useful only after response is complete.

Correct Answer: 2

Explanation:

Threat intelligence can provide useful context about adversary techniques, infrastructure, campaigns, and targeting patterns. Hunters can translate this information into testable hypotheses and searches. Intelligence indicators may become outdated or may overlap with legitimate infrastructure, so local validation is still required. The strongest hunting conclusions combine external intelligence with endpoint, identity, and network context from the organization’s own environment.

Question 157.

A hunter discovers an unapproved remote access utility running on several workstations. What is the most appropriate next step?

  1. Investigate installation source, execution history, users, destinations, and whether the activity matches authorized business use
    2. Immediately assume every instance is malicious
    3. Ignore it because remote access tools can be legitimate
    4. Delete all endpoint evidence

Correct Answer: 1

Explanation:

Remote access utilities can be legitimate support tools or attacker-controlled access mechanisms. The hunter should determine who installed the software, when it first appeared, which users executed it, what systems it contacted, and whether the activity aligns with approved business processes. Cross-host comparison may reveal a common installation mechanism or external destination. Context is required before deciding whether the tool is authorized or malicious.

Question 158.

Which behavior most strongly suggests privilege escalation?

  1. A browser starts normally
    2. A user opens an approved document
    3. A scheduled backup completes
    4. A low-privilege process unexpectedly results in execution under a highly privileged account

Correct Answer: 4

Explanation:

An unexpected transition from low privilege to high privilege can indicate exploitation, token abuse, or misuse of an elevation mechanism. The hunter should inspect the process ancestry, account context, command line, privilege transition, and actions performed after elevation. Legitimate installers and administrative tasks can also elevate privileges, so baseline behavior and software context should be considered.

Question 159.

Which investigation method is most useful for understanding the sequence of events during a suspected endpoint compromise?

  1. Reviewing only the detection title
    2. Searching only one hash
    3. Building a chronological timeline of process, file, authentication, and network activity
    4. Reviewing only installed applications

Correct Answer: 3

Explanation:

A timeline helps reconstruct how activity unfolded and can reveal initial execution, persistence, credential access, network communication, and follow-on actions. Temporal context often exposes relationships that are not obvious when events are viewed individually. A good timeline can also identify previously unnoticed activity before and after the original detection, helping the hunter understand the broader attack chain.

Question 160.

Which action best completes a productive threat hunt after malicious activity has been confirmed?

  1. Delete the investigation records
    2. Document findings, establish scope, support containment, and turn useful hunting logic into reusable detections or future hunt analytics
    3. Disable relevant telemetry
    4. Leave the activity undocumented

Correct Answer: 2

Explanation:

A completed threat hunt should improve both current response and future defensive capability. The hunter should document affected systems, users, timelines, indicators, and behavioral findings, then coordinate containment or remediation as needed. Useful hunt queries can be refined into reusable detections or analytics. Lessons learned may also reveal telemetry gaps or new hypotheses for future hunts.