CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part12 Q221-240

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 221.

A Falcon Hunter identifies a suspicious executable that was launched by a script interpreter and then created multiple child processes. What should the hunter investigate first?

  1. The complete process tree, command lines, user context, file activity, and network connections
    2. Only the executable filename
    3. The endpoint’s display settings
    4. Printer configuration

Correct Answer: 1

Explanation:

The complete execution chain provides the strongest context for understanding suspicious activity. The hunter should examine how the executable was launched, what command-line arguments were used, which child processes were created, what files were written, and whether external connections followed. Script interpreters are commonly used for both legitimate administration and malicious activity, so behavior and surrounding context are more important than the executable name alone.

Question 222.

Which behavior most strongly suggests persistence through a scheduled task?

  1. A user launches a standard application
    2. A normal software update completes
    3. A routine inventory scan runs
    4. A newly created task repeatedly launches an unfamiliar executable after user logon

Correct Answer: 4

Explanation:

A newly created scheduled task that repeatedly launches an unfamiliar executable can provide persistence across sessions. The hunter should inspect the task definition, creation time, creating process, executing account, referenced executable, and subsequent activity. Scheduled tasks are also used legitimately, so the hunter should compare the behavior with normal administrative and software deployment patterns before classifying it as malicious.

Question 223.

Which telemetry is most valuable when investigating suspected lateral movement using remote services?

  1. Screen brightness
    2. Printer queues
    3. Source and destination hosts, authentication events, account activity, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Remote-service activity should be investigated by correlating authentication with endpoint execution. The hunter should identify where the connection originated, which account was used, what destination was accessed, and what process or command ran afterward. This helps distinguish legitimate administration from attacker movement. Reviewing only one event type can miss the sequence connecting authentication to remote execution.

Question 224.

Which approach is most effective when investigating suspicious use of a built-in scripting engine?

  1. Treat every use of the scripting engine as malicious
    2. Analyze command lines, parent-child relationships, users, created files, and related network activity
    3. Ignore the activity because the binary is signed
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Built-in scripting tools are frequently used by administrators and attackers. The hunter should therefore focus on how the tool is invoked, what arguments are passed, which process launched it, which files it creates, and what network activity follows. A trusted or signed executable can still be abused. Contextual analysis provides far more value than classifying the scripting engine itself as malicious or safe.

Question 225.

A Falcon Hunter discovers an uncommon executable running on a high-value server. What is the best next step?

  1. Investigate the file hash, signer, path, parent process, command line, user, and related activity
    2. Automatically classify it as malicious because it is rare
    3. Ignore it because it appears on only one server
    4. Delete all associated telemetry

Correct Answer: 1

Explanation:

Rarity is useful for prioritization, but it does not prove maliciousness. Specialized servers may run uncommon business applications. The hunter should evaluate the executable’s signer, path, hash, ancestry, user context, command line, and network behavior. Combining rarity with suspicious execution patterns or unusual destinations provides a stronger basis for determining whether the activity represents a threat.

Question 226.

Which pattern most strongly suggests command-and-control beaconing?

  1. A local application reads a configuration file
    2. A user opens an approved document
    3. A routine patch checks for updates
    4. A process repeatedly contacts the same uncommon destination at nearly regular intervals

Correct Answer: 4

Explanation:

Repeated outbound connections to an uncommon destination at similar intervals can indicate beaconing behavior. The hunter should examine the initiating process, connection timing, destination, affected hosts, and DNS activity. Legitimate applications can also communicate periodically, so baseline behavior is important. Beaconing becomes more suspicious when paired with unusual execution, persistence, or credential-related activity.

Question 227.

Which event pattern is most relevant when hunting for possible credential access followed by lateral movement?

  1. A user opens a spreadsheet
    2. A scheduled backup starts
    3. An unusual process accesses credential-related resources and is followed by remote authentication to other hosts
    4. A browser loads a known website

Correct Answer: 3

Explanation:

The combination of suspicious credential access and subsequent remote authentication may indicate that captured credentials were reused for lateral movement. The hunter should inspect the process responsible for credential access, the affected account, source system, destination hosts, and resulting processes. Correlating endpoint and identity telemetry can help determine whether the sequence represents legitimate administration or adversary activity.

Question 228.

Which statement best describes the value of grouping search results by hostname?

  1. It proves every affected host is compromised.
    2. It helps reveal where suspicious activity is concentrated and how widely it is distributed.
    3. It eliminates the need for event-level investigation.
    4. It is useful only for asset inventory.

Correct Answer: 2

Explanation:

Grouping by hostname helps hunters quickly see whether suspicious behavior is limited to one endpoint or distributed across many systems. Hosts with unusually high event counts or unique patterns may deserve priority. Aggregation is useful for identifying scope and outliers, but individual events still need to be reviewed for process, user, timing, and network context.

Question 229.

A hunter observes an email client spawning a script interpreter that downloads a file. What should be investigated next?

  1. The message or attachment source, process chain, command line, downloaded file, and destination
    2. Only the user’s email address
    3. Printer settings
    4. Desktop theme

Correct Answer: 1

Explanation:

An email client launching a script interpreter and downloading a file is a suspicious chain that may indicate malicious attachment execution or exploitation. The hunter should inspect the original email or attachment, process ancestry, command-line parameters, download source, file hash, and subsequent execution. Looking at the full sequence helps establish how the suspicious activity began and whether similar behavior occurred elsewhere.

Question 230.

Which behavior most strongly suggests data staging before exfiltration?

  1. A user opens a browser
    2. A normal application writes a small cache file
    3. A scheduled update downloads
    4. A process copies many documents into one location and compresses them into a large archive

Correct Answer: 4

Explanation:

Collecting and compressing files into one location can indicate preparation for exfiltration. The hunter should identify which files were gathered, the responsible process, user context, archive path, and whether unusual outbound communication followed. Legitimate backup or archival software can perform similar actions, so the activity should be compared with normal host behavior and expected business processes.

Question 231.

Which hunting method is most effective when adversaries frequently change hashes, filenames, and network indicators?

  1. Search only exact hashes
    2. Search only filenames
    3. Hunt for behavioral patterns such as process ancestry, command-line structures, and recurring activity sequences
    4. Ignore endpoint telemetry

Correct Answer: 3

Explanation:

Static indicators can change rapidly, while adversary behaviors often remain more consistent. Process relationships, command-line patterns, persistence techniques, and event sequences can provide more durable hunting logic. Exact hashes and domains are still valuable for rapid scoping, but behavioral hunting can identify related activity after attackers change superficial artifacts.

Question 232.

Which statement best describes the purpose of baselining network behavior for a host?

  1. It proves every common destination is safe.
    2. It helps identify unusual destinations, connection patterns, or volumes that differ from normal behavior.
    3. It removes the need for investigation.
    4. It automatically blocks all rare connections.

Correct Answer: 2

Explanation:

A network baseline helps the hunter understand which destinations, protocols, and communication patterns are normally observed for a system. Significant deviations can become useful hunting leads. Rare destinations may be legitimate, and common infrastructure can still be abused, so baseline data should guide prioritization rather than automatically classify activity as malicious.

Question 233.

A service account begins launching interactive processes on several user workstations. What should the hunter investigate first?

  1. Source systems, authentication method, affected hosts, process activity, and whether the behavior matches the account’s intended purpose
    2. Only the account name
    3. Printer history
    4. Screen resolution

Correct Answer: 1

Explanation:

Service accounts typically perform predictable automated functions. Interactive process execution on user workstations may indicate credential compromise or misuse. The hunter should identify where the activity originated, how the account authenticated, which processes it launched, and whether those actions align with its documented purpose. Deviations in service-account behavior are often strong hunting signals because normal patterns tend to be stable.

Question 234.

Which behavior most strongly suggests defense evasion?

  1. A user opens a standard application
    2. A routine patch installs
    3. A scheduled inventory process runs
    4. A process stops security services, modifies exclusions, and removes local logs

Correct Answer: 4

Explanation:

Stopping security services, changing exclusions, and deleting logs are all behaviors associated with reducing defensive visibility. When they appear together, the activity is particularly suspicious. The hunter should identify the responsible process, user, parent process, commands, and subsequent actions. Centralized telemetry may be especially important if local evidence has been altered or removed.

Question 235.

A suspicious domain appears in network events from several endpoints. Which action is best for determining its importance?

  1. Review only external reputation data
    2. Ignore which processes contacted the domain
    3. Correlate the domain with hosts, processes, users, timestamps, and DNS activity
    4. Delete the matching events

Correct Answer: 3

Explanation:

Correlating the domain with local telemetry helps reveal how it was used across the environment. The hunter can identify which hosts contacted it, which processes initiated communication, which users were active, and whether the timing aligns with other suspicious events. External reputation can add context but should not replace investigation of enterprise telemetry.

Question 236.

Which statement best describes how MITRE ATT&CK can help guide a hunt?

  1. It automatically detects every attack.
    2. It provides a structured way to categorize observed behaviors and identify related techniques worth investigating.
    3. It replaces endpoint event data.
    4. It proves that every mapped behavior is malicious.

Correct Answer: 2

Explanation:

MITRE ATT&CK provides a common framework for adversary tactics and techniques. Hunters can map observed behaviors to techniques and use those mappings to identify likely follow-on activity. For example, evidence of credential access may prompt additional searches for lateral movement or persistence. ATT&CK organizes investigation but does not replace local telemetry or contextual analysis.

Question 237.

A hunter discovers a remote administration utility that is not part of the organization’s approved software list. What should be done first?

  1. Investigate installation source, execution history, users, destinations, and whether there is a legitimate business justification
    2. Automatically classify every instance as malicious
    3. Ignore it because remote administration software can be legitimate
    4. Delete all endpoint logs

Correct Answer: 1

Explanation:

An unapproved remote administration tool may be legitimate shadow IT or attacker-controlled access. The hunter should determine how it was installed, who used it, which systems or external destinations it contacted, and whether its presence aligns with business needs. Cross-host analysis may reveal a common user, installer, or external endpoint that helps establish whether the activity is authorized.

Question 238.

Which behavior most strongly suggests privilege escalation?

  1. A browser launches normally
    2. A scheduled maintenance task completes
    3. An approved application starts
    4. A standard-user process unexpectedly results in execution under a highly privileged security context

Correct Answer: 4

Explanation:

An unexpected transition from standard-user execution to a highly privileged context may indicate exploitation or abuse of an elevation mechanism. The hunter should inspect process ancestry, account context, command line, the elevation method, and activity performed after privilege was gained. Legitimate installers can also elevate, so signer information and historical behavior should be considered.

Question 239.

Which investigation technique is most useful for reconstructing how an intrusion progressed across one endpoint?

  1. Reviewing only the detection severity
    2. Searching only one hash
    3. Building a chronological timeline of process, authentication, file, and network events
    4. Reviewing only installed applications

Correct Answer: 3

Explanation:

A chronological timeline helps connect isolated events into a coherent attack sequence. It can reveal initial execution, persistence, credential access, network communication, lateral-movement preparation, and other follow-on actions. Individual detections may represent only one part of the intrusion. Timelining can expose relationships and activity that were not obvious when each event was viewed separately.

Question 240.

Which action best completes a successful threat hunt after malicious activity has been confirmed?

  1. Delete the investigation notes
    2. Document findings, determine scope, coordinate containment and remediation, and improve future detection or hunting logic
    3. Disable relevant telemetry
    4. Leave the hunt undocumented

Correct Answer: 2

Explanation:

A successful hunt should improve both immediate incident response and long-term defensive capability. The hunter should document affected hosts, users, timelines, behaviors, and important indicators, then coordinate response actions where necessary. Useful queries and behavioral patterns can be converted into reusable detections or future hunt analytics. Lessons learned can also reveal telemetry gaps and strengthen future hunting hypotheses.