View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 161.
A Falcon Hunter notices that an unfamiliar process launches from a temporary directory and immediately creates a child PowerShell process. What should the hunter investigate first?
- The process tree, command lines, file hash, user context, and subsequent network or file activity
2. The endpoint’s wallpaper
3. Only the parent process name
4. Printer configuration
Correct Answer: 1
Explanation:
Execution from a temporary directory followed by PowerShell activity can indicate downloaded malware, script-based execution, or a legitimate installer. The hunter should review the full process ancestry, command-line arguments, file hash, user context, and follow-on behavior. Network connections and created files can help reveal whether a payload was retrieved or additional activity occurred. A single suspicious characteristic is not enough, so multiple contextual signals should be evaluated together.
Question 162.
Which behavior most strongly suggests persistence through account modification?
- A user opens a normal browser session
2. A scheduled inventory task completes
3. A routine application update occurs
4. A suspicious process creates a new local administrator account
Correct Answer: 4
Explanation:
Creating a new privileged account can provide persistent access even if the original compromised identity is disabled. The hunter should determine which process created the account, the user context, when the account was created, and whether it was subsequently used for logon or remote access. Legitimate account provisioning can also occur, so the activity should be compared with expected administrative workflows and change records.
Question 163.
Which telemetry is most useful when investigating suspected lateral movement using remote desktop activity?
- Local font settings
2. Printer queues
3. Source host, destination host, account used, logon events, and follow-on process activity
4. Display brightness
Correct Answer: 3
Explanation:
Remote desktop activity becomes meaningful when correlated with the source system, destination, account, authentication time, and actions performed after the session begins. The hunter should also compare the activity with historical behavior and the user’s role. Legitimate administrators may use remote desktop routinely, while unexpected access from unusual workstations or accounts can indicate lateral movement.
Question 164.
Which approach is most effective when hunting for malicious use of a signed Windows utility?
- Assume signed utilities are always safe
2. Evaluate process ancestry, command line, execution path, user, and related activity
3. Ignore all signed binaries
4. Search only the filename
Correct Answer: 2
Explanation:
Digital signatures can confirm software origin but do not guarantee legitimate use. Attackers frequently abuse trusted utilities for execution, discovery, persistence, or defense evasion. The hunter should focus on how the utility is invoked, which process launched it, the command-line parameters, user context, path, and follow-on behavior. Signed software can still participate in malicious execution chains.
Question 165.
A Falcon Hunter identifies a process that is common across the environment but behaves differently on one host. What should the hunter do?
- Investigate the unusual command line, parent process, user, and network activity on that host
2. Ignore it because the executable is common
3. Delete all events involving the process
4. Assume all instances are malicious
Correct Answer: 1
Explanation:
Common executables can still be abused. The important distinction may be how the process behaves on a specific host. An unusual command line, parent process, user, path, or destination can indicate malicious use even when the executable itself is widely present. Hunting should therefore consider behavioral deviations in addition to file prevalence.
Question 166.
Which pattern most strongly suggests automated command-and-control traffic?
- A user launches an approved application
2. A scheduled backup completes
3. A process performs one legitimate update check
4. A process repeatedly contacts the same external destination using similar intervals over a long period
Correct Answer: 4
Explanation:
Repeated connections at consistent or near-consistent intervals may indicate automated beaconing to command-and-control infrastructure. The hunter should examine timing, destination rarity, process identity, affected hosts, and whether communication continues when no user is active. Legitimate software can also check services periodically, so baseline and application purpose should be considered before concluding the behavior is malicious.
Question 167.
Which event pattern is most relevant when investigating suspected password or credential theft?
- A normal browser session
2. A routine system update
3. An unusual privileged process accessing authentication-related resources followed by new logon activity
4. A user printing a document
Correct Answer: 3
Explanation:
Credential-access activity is more concerning when suspicious access to authentication resources is followed by new or unusual logons. The hunter should examine the process, privileges, parent, account context, and subsequent authentication events. This sequence may indicate that credentials were obtained and then reused. Legitimate security tools can interact with sensitive resources, so process identity and expected behavior should also be considered.
Question 168.
Which statement best describes the value of grouping events by destination domain during hunting?
- It proves every rare domain is malicious.
2. It can reveal which destinations are common, rare, or shared across multiple affected hosts.
3. It replaces process analysis.
4. It is useful only for inventory management.
Correct Answer: 2
Explanation:
Grouping events by domain can help hunters identify uncommon destinations and determine whether several hosts are contacting the same external infrastructure. This can reveal coordinated activity or help prioritize suspicious destinations for further investigation. Hunters should then pivot into the responsible processes, users, and timestamps. Domain rarity alone does not establish maliciousness.
Question 169.
A hunter observes a browser process launching a command interpreter, which then executes a newly downloaded file. What is the best next step?
- Investigate the browser activity, process chain, command line, downloaded file, and network destination
2. Assume the chain is normal browser behavior
3. Ignore the command interpreter because it is built into the system
4. Delete the events immediately
Correct Answer: 1
Explanation:
A browser launching a command interpreter followed by execution of a downloaded file is a suspicious chain that may indicate exploitation, malicious download activity, or social engineering. The hunter should inspect the browser event, process ancestry, command-line parameters, file hash, download source, and subsequent activity. The full sequence provides more context than any single process in isolation.
Question 170.
Which behavior most strongly suggests collection and staging of data?
- A user opens a routine application
2. A standard service writes a small log
3. An approved update completes
4. A process enumerates many documents, copies them to one directory, and compresses them into an archive
Correct Answer: 4
Explanation:
Collecting files into one location and compressing them can indicate staging before exfiltration. The hunter should examine which data was collected, the process responsible, user context, archive destination, and whether outbound transfers followed. Backup and administrative tools can perform similar actions, so the activity should be compared with normal behavior and expected business processes.
Question 171.
Which hunting approach is most effective against attackers who frequently rotate network indicators but continue using the same execution techniques?
- Exact IP searches only
2. Domain searches only
3. Behavioral hunting based on execution patterns, process relationships, and command lines
4. Ignoring endpoint behavior
Correct Answer: 3
Explanation:
Network infrastructure can be changed quickly, making IP addresses and domains short-lived indicators. Behavioral patterns such as process ancestry, command syntax, persistence methods, or credential-access techniques are often more durable. Behavioral hunting can therefore identify related activity even after network indicators change. Static indicators remain useful for scoping but should not be the only hunting method.
Question 172.
Which statement best describes the purpose of comparing activity against a host baseline?
- It guarantees that any rare event is malicious.
2. It helps identify deviations from the host’s normal processes, users, and network behavior.
3. It replaces threat intelligence.
4. It eliminates the need for investigation.
Correct Answer: 2
Explanation:
A host baseline helps the hunter understand which processes, users, network destinations, and execution patterns are normally observed on a system. Significant deviations can become valuable investigative leads. However, abnormal behavior may still be legitimate, and common behavior can sometimes be malicious. Baselines help prioritize investigation rather than automatically classify events.
Question 173.
A user account begins logging onto systems that are outside the user’s normal business role. What should the hunter investigate first?
- Source host, authentication method, destination systems, timing, and actions performed afterward
2. Only the user’s department name
3. Printer history
4. Desktop theme
Correct Answer: 1
Explanation:
Unexpected access to systems outside a user’s normal role can indicate credential theft, privilege misuse, or a legitimate temporary assignment. The hunter should examine where the activity originated, how authentication occurred, which systems were accessed, and what processes or commands followed. Historical behavior and user role provide useful context when determining whether the activity is expected.
Question 174.
Which behavior most strongly suggests defense evasion?
- A user opens an approved application
2. A normal update runs
3. A scheduled scan completes
4. A process disables security tooling, clears logs, and removes files related to its execution
Correct Answer: 4
Explanation:
Disabling security controls, clearing logs, and deleting artifacts are common attempts to reduce detection and hinder forensic analysis. When these behaviors occur together, they are particularly suspicious. The hunter should identify the responsible process, account, commands, and subsequent activity. Any telemetry stored outside the affected host may be especially valuable because local evidence may have been altered.
Question 175.
A hunter identifies a suspicious IP address in one endpoint’s telemetry. Which approach best determines whether the activity is widespread?
- Review only external reputation information
2. Search only the original endpoint
3. Search the IP across enterprise telemetry and identify associated hosts, users, processes, and times
4. Ignore the process that made the connection
Correct Answer: 3
Explanation:
Enterprise-wide searching can reveal whether the IP appears on multiple endpoints and which processes or users were associated with the connections. This helps establish scope and identify common execution patterns. External reputation can provide context, but local telemetry is necessary to understand whether and how the address was used in the organization.
Question 176.
Which statement best describes how a hunter should use MITRE ATT&CK during an investigation?
- Use it only to name malware families.
2. Use tactics and techniques to categorize observed behavior and guide related hunting questions.
3. Treat every technique mapping as confirmed compromise.
4. Use it instead of endpoint telemetry.
Correct Answer: 2
Explanation:
MITRE ATT&CK gives hunters a common language for describing adversary behaviors. Mapping observed activity to tactics and techniques can help identify likely follow-on actions and guide additional searches. For example, evidence of credential access may lead to hunting for lateral movement. ATT&CK provides structure but does not replace local telemetry or prove that activity is malicious.
Question 177.
A hunter discovers an unfamiliar remote-control application running under a user’s account. What is the best next step?
- Review installation source, execution history, user activity, network destinations, and whether the tool is authorized
2. Immediately assume compromise without further investigation
3. Ignore it because remote-control tools are legitimate software
4. Delete all logs from the endpoint
Correct Answer: 1
Explanation:
Remote-control software can be used for legitimate support or malicious persistence. The hunter should determine whether the tool is approved, how it was installed, which user launched it, which systems it contacted, and whether its behavior aligns with business use. Comparing activity across hosts may reveal common deployment or external infrastructure.
Question 178.
Which behavior most strongly suggests privilege escalation?
- A normal user launches a standard application
2. A scheduled backup completes
3. A browser opens normally
4. A process running with standard-user rights unexpectedly spawns a highly privileged process
Correct Answer: 4
Explanation:
An unexpected transition from standard-user execution to a highly privileged process may indicate exploitation, token abuse, or another privilege-escalation technique. The hunter should examine process ancestry, the account, command line, elevation mechanism, and actions performed afterward. Legitimate installers can also elevate privileges, so context is essential.
Question 179.
Which investigation technique is most useful for understanding an attack sequence across time?
- Reviewing only the detection title
2. Searching only a single filename
3. Constructing a timeline of process, authentication, file, and network events
4. Reviewing only host inventory information
Correct Answer: 3
Explanation:
Timelines help hunters understand the order and relationship of events. They can reveal initial execution, persistence, credential access, lateral movement, network communication, and other follow-on actions. A single detection may represent only one point in a broader sequence. Chronological reconstruction helps uncover related activity that was not initially flagged.
Question 180.
Which action best completes a successful threat hunt after malicious activity has been confirmed?
- Delete the hunt results
2. Document findings, determine scope, coordinate response, and convert useful behaviors into future detection or hunting logic
3. Stop collecting relevant telemetry
4. Leave findings undocumented
Correct Answer: 2
Explanation:
A successful hunt should improve immediate response and future security capability. The hunter should document affected hosts, users, indicators, behavior, and timelines, then support containment and remediation where needed. Useful queries or patterns can be transformed into reusable detection content. Lessons learned can also expose visibility gaps and improve future hunting hypotheses.