View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 181.
A Falcon Hunter identifies a suspicious process that creates several files and then launches a second executable from an uncommon directory. What should the hunter investigate first?
- The process ancestry, created files, command lines, user context, and subsequent activity
2. Only the hostname
3. The user’s desktop wallpaper
4. Printer configuration
Correct Answer: 1
Explanation:
The process ancestry and file-creation sequence can reveal how the suspicious activity developed. The hunter should determine which parent created the files, what the second executable is, where it came from, and what actions followed. Command-line details, user context, hashes, network connections, and execution timing provide additional context. Investigating the full chain is more useful than focusing only on an individual filename or host.
Question 182.
Which behavior most strongly suggests persistence through service modification?
- A user opens a browser
2. A scheduled report runs
3. A normal application update completes
4. An existing service is modified to launch an unfamiliar executable at startup
Correct Answer: 4
Explanation:
Changing an existing service so that it launches an unfamiliar executable can provide persistence and may also help an attacker blend into normal system behavior. The hunter should inspect which process modified the service, the account involved, the new binary path, and subsequent service execution. Legitimate software updates can modify services too, so timing, signer information, and surrounding activity should be considered.
Question 183.
Which telemetry is most valuable when investigating suspicious remote command execution?
- Display settings
2. Printer history
3. Source host, destination host, authentication events, process creation, and command-line activity
4. Local font inventory
Correct Answer: 3
Explanation:
Remote command execution typically involves both authentication and endpoint activity. The hunter should identify where the connection originated, which account was used, which destination system was affected, and what process or command executed afterward. This context helps distinguish legitimate administration from adversary lateral movement. Reviewing only authentication events may not reveal what happened after access was obtained.
Question 184.
Which approach is most effective when hunting for suspicious use of Windows Management Instrumentation or another remote management mechanism?
- Treat every remote management action as malicious
2. Evaluate source, destination, account, command line, timing, and resulting process activity
3. Ignore remote management because administrators use it
4. Search only the executable name
Correct Answer: 2
Explanation:
Remote management technologies are legitimate but can also be abused for lateral movement or remote execution. The hunter should focus on contextual factors such as who initiated the action, from where, against which host, and what executed afterward. Unusual timing, uncommon accounts, rare source systems, or suspicious child processes can help distinguish administrative activity from malicious use.
Question 185.
A Falcon Hunter finds a commonly used system utility executing with an unusual command line on one endpoint. What is the best next action?
- Investigate the command line, parent process, user, execution path, and related behavior
2. Ignore the event because the utility is common
3. Delete all events involving the utility
4. Assume every use of the utility is malicious
Correct Answer: 1
Explanation:
Common system utilities can be abused by attackers, so prevalence of the executable does not automatically make the activity safe. The unusual command line may reveal suspicious arguments or behavior. Parent process, user, execution path, file activity, and network connections provide additional context. Behavioral deviations are often more useful than executable rarity when investigating living-off-the-land techniques.
Question 186.
Which pattern most strongly suggests possible command-and-control communication?
- A user launches a local application
2. A scheduled inventory job runs
3. A normal update checks for patches
4. A process repeatedly communicates with a rare destination using similar timing and packet sizes
Correct Answer: 4
Explanation:
Regular timing and similar communication patterns can indicate beaconing behavior associated with command-and-control infrastructure. The hunter should examine the initiating process, destination, timing intervals, traffic volume, DNS activity, and host distribution. Legitimate software can also generate periodic communication, so baselining and process context are important before making a malicious determination.
Question 187.
Which event pattern is most relevant when hunting for possible credential reuse after theft?
- A standard software update
2. A normal browser launch
3. Suspicious credential-access activity followed by unusual authentications to additional systems
4. A user prints a document
Correct Answer: 3
Explanation:
Credential theft becomes especially significant when followed by unusual authentication activity. The hunter should connect the original credential-access event with new logons, remote connections, and resulting process execution. This sequence may indicate that stolen credentials were successfully reused for lateral movement. Identity and endpoint telemetry should be correlated to establish whether the behavior is expected or malicious.
Question 188.
Which statement best describes the value of grouping hunting results by user account?
- It automatically confirms account compromise.
2. It can reveal which identities are most frequently associated with suspicious activity.
3. It eliminates the need for host analysis.
4. It is useful only for access administration.
Correct Answer: 2
Explanation:
Grouping events by user can help hunters identify accounts that appear disproportionately in suspicious activity. A user associated with many unusual processes, hosts, or remote sessions may warrant closer examination. Aggregation provides a useful summary but should be followed by event-level review. The account’s normal role, historical behavior, and authentication context are important for determining whether the activity is legitimate.
Question 189.
A hunter observes an email client launching a command shell that downloads a script from an external site. What should the hunter investigate next?
- The email event, attachment or message source, process chain, command line, download, and resulting execution
2. Only the user’s email address
3. The endpoint’s screen resolution
4. Printer settings
Correct Answer: 1
Explanation:
An email client spawning a command shell and downloading a script is a suspicious chain that may indicate malicious attachment execution or exploitation. The hunter should examine the original message or attachment, process ancestry, command-line arguments, destination, downloaded content, and subsequent activity. The full sequence helps determine how execution began and whether the same behavior occurred on other hosts.
Question 190.
Which behavior most strongly suggests staging before exfiltration?
- A normal application writes a small configuration file
2. A browser opens a common website
3. A routine patch downloads
4. A process copies sensitive files into one location, compresses them, and then starts outbound communication
Correct Answer: 4
Explanation:
Collecting sensitive files into one location and compressing them before outbound communication is a strong data-staging and exfiltration hypothesis. The hunter should identify the files collected, process responsible, user context, archive path, destination, and transfer volume. Legitimate backup or synchronization software can create similar patterns, so comparison with baseline and expected business behavior remains important.
Question 191.
Which hunting strategy is most effective when attackers frequently rotate domains and IP addresses?
- Search only one known IP
2. Search only one known domain
3. Hunt for durable behaviors such as process relationships, command lines, and communication patterns
4. Ignore endpoint telemetry
Correct Answer: 3
Explanation:
Domains and IP addresses can change quickly, making them short-lived indicators. Behavioral patterns often remain more consistent, such as unusual process ancestry, scripting activity, persistence methods, or communication timing. Hunting for these behaviors provides better resilience against infrastructure changes. Static indicators still help with immediate scoping but should be combined with behavioral analysis for broader coverage.
Question 192.
Which statement best describes the purpose of host baselining?
- It automatically labels all uncommon processes as malicious.
2. It helps identify deviations from the host’s normal processes, users, and network activity.
3. It eliminates the need for detailed investigation.
4. It guarantees that frequent behavior is safe.
Correct Answer: 2
Explanation:
Host baselining provides a reference for what is normally observed on a system. When a new user, process, command line, or destination appears, the deviation can become a useful hunting lead. However, unusual activity may be legitimate, and common behavior can sometimes be abused. Baselines help prioritize investigation rather than automatically classify events.
Question 193.
A service account that normally runs automated jobs begins authenticating interactively to several workstations. What should the hunter do first?
- Investigate the source systems, authentication type, destinations, timing, and activity performed after login
2. Ignore the activity because the service account is valid
3. Disable all authentication logging
4. Increase the account’s privileges
Correct Answer: 1
Explanation:
A service account behaving differently from its normal automated pattern is a meaningful anomaly. Interactive logons to workstations may indicate credential compromise or misuse. The hunter should determine where the activity originated, what authentication mechanism was used, which systems were accessed, and what processes executed afterward. Service accounts often have predictable behavior, making deviations particularly useful hunting signals.
Question 194.
Which behavior most strongly suggests defense evasion?
- A user opens an approved document
2. A normal update installs
3. A scheduled backup completes
4. A process disables endpoint security, modifies exclusions, and deletes local logs
Correct Answer: 4
Explanation:
The combination of disabling security software, modifying exclusions, and deleting logs strongly suggests an attempt to evade detection. The hunter should inspect the responsible process, user, parent process, commands, and any follow-on execution. Multiple defensive-control changes occurring together should receive high investigative priority. Telemetry stored outside the endpoint can be especially useful if local evidence was removed.
Question 195.
A suspicious domain appears across several endpoint events. Which action best helps establish its role in the investigation?
- Review only its external reputation
2. Ignore the processes that contacted it
3. Correlate the domain with hosts, processes, users, DNS activity, and timestamps across the environment
4. Delete the matching events
Correct Answer: 3
Explanation:
Correlating the domain with local endpoint and DNS telemetry provides context about how it was used. The hunter can identify which hosts connected, which processes initiated the activity, which users were active, and whether the timing aligns with other suspicious behavior. External reputation can add context but does not replace enterprise telemetry. The same domain may be associated with different activity on different systems.
Question 196.
Which statement best describes how MITRE ATT&CK can support a Falcon Hunter?
- It identifies every malicious file hash automatically.
2. It provides a structured way to map observed adversary behaviors and identify related techniques to investigate.
3. It replaces event searches.
4. It proves an incident exists whenever a technique is mapped.
Correct Answer: 2
Explanation:
MITRE ATT&CK provides a common language for tactics and techniques used by adversaries. Hunters can map observed behavior to ATT&CK and use those mappings to identify likely related activity. For example, evidence of persistence may lead to searches for privilege escalation or lateral movement. ATT&CK organizes investigation but does not replace endpoint telemetry or prove that an event is malicious.
Question 197.
A hunter discovers a remote access tool installed on several endpoints without an approved software deployment record. What should be done first?
- Investigate installation source, execution history, users, external destinations, and whether the tool is authorized
2. Ignore it because remote access software is commonly legitimate
3. Delete all host telemetry
4. Assume every endpoint is compromised without further investigation
Correct Answer: 1
Explanation:
Remote access software can support legitimate business functions, but unapproved deployment across several endpoints warrants investigation. The hunter should determine how the tool was installed, which accounts used it, where it connected, and whether its presence aligns with documented business use. Cross-host comparison can reveal a common installer, user, or external infrastructure that helps establish the tool’s role.
Question 198.
Which behavior most strongly suggests privilege escalation?
- A standard user opens a browser
2. A normal scheduled task executes
3. An approved application starts
4. A standard-user process unexpectedly causes execution under a system-level security context
Correct Answer: 4
Explanation:
An unexpected transition from standard-user execution to system-level privileges can indicate exploitation or abuse of an elevation mechanism. The hunter should examine the process tree, account, command line, elevation path, and subsequent actions performed with the higher privileges. Legitimate installers may also produce privilege transitions, so context, signer information, and historical behavior are essential.
Question 199.
Which investigation technique is most useful for determining how a compromise progressed from initial execution to follow-on actions?
- Reviewing only the detection severity
2. Searching only one hash
3. Constructing a chronological timeline of process, file, network, and authentication activity
4. Reviewing only host inventory information
Correct Answer: 3
Explanation:
A chronological timeline helps connect events into a coherent sequence. It can reveal initial execution, persistence, credential access, remote activity, command-and-control communication, and other follow-on actions. Individual detections often show only one stage of an intrusion. Timelining provides broader context and can reveal events that were not independently considered suspicious.
Question 200.
Which action best completes a successful threat hunt after malicious behavior has been validated?
- Delete the investigation records
2. Document findings, establish scope, coordinate response, and improve future detection and hunting content
3. Disable relevant telemetry
4. Leave the hunt undocumented
Correct Answer: 2
Explanation:
A successful hunt should support immediate response and improve future defensive capability. Findings should document affected systems, users, timelines, behaviors, and important indicators. Confirmed malicious activity should be coordinated with response teams for containment and remediation. Useful hunt queries and behavioral patterns can be converted into reusable detections, while lessons learned can improve future hypotheses and telemetry coverage.