CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part14 Q261-280

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 261.

A Falcon Hunter identifies a suspicious executable that appears shortly after a user downloads an archive from the internet. What should the hunter investigate first?

  1. The download source, extracted files, process ancestry, command line, user context, and subsequent activity
    2. Only the executable filename
    3. Printer configuration
    4. The user’s desktop theme

Correct Answer: 1

Explanation:

When suspicious execution follows an internet download, the hunter should reconstruct the chain from delivery to execution. Reviewing the download source, archive contents, extracted files, process tree, command lines, and subsequent file or network activity can help determine whether the archive delivered malicious content. User context and timing are also important. The filename alone is weak evidence because adversaries can rename files easily, while the broader execution sequence provides stronger investigative value.

Question 262.

Which behavior most strongly suggests persistence through a registry-based startup mechanism?

  1. A normal browser session begins
    2. A routine software update runs
    3. An approved application saves a configuration file
    4. An unfamiliar process creates an entry that causes an executable to run automatically at user logon

Correct Answer: 4

Explanation:

Registry-based startup entries can allow an executable to run automatically whenever a user signs in. The hunter should determine which process created the entry, the user associated with it, the referenced executable, and whether the same behavior appears elsewhere. Legitimate applications may also create startup entries, so timing, path, signer information, and surrounding activity should be considered before classifying the behavior as malicious.

Question 263.

Which telemetry is most useful when investigating suspicious use of a newly created service for lateral movement?

  1. Screen brightness
    2. Printer history
    3. Source and destination hosts, authentication events, service creation, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

A newly created service on a remote host can be associated with legitimate administration or lateral movement. The hunter should correlate the source host, account used, authentication events, service creation time, configured binary, and resulting process execution. This sequence helps establish whether the service was created remotely and what it executed. Reviewing only the service name or binary without authentication context may miss the broader movement pattern.

Question 264.

Which approach is most effective when a hunter suspects malicious use of rundll32.exe or another trusted Windows utility?

  1. Treat every execution of the utility as malicious
    2. Analyze the command line, parent process, loaded content, user context, path, and follow-on activity
    3. Ignore the utility because it is Microsoft-signed
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Trusted utilities can be abused to execute malicious content while blending into normal system activity. The hunter should focus on how the utility was invoked, what arguments or content it referenced, which parent process launched it, who executed it, and what happened afterward. Signed binaries are not automatically safe in every context. Behavioral context is more reliable than the executable name alone.

Question 265.

A Falcon Hunter sees a process that normally runs from a system directory executing instead from a user-writable folder. What should the hunter do?

  1. Investigate the path, hash, signer, parent process, command line, and related behavior
    2. Ignore it because the filename is familiar
    3. Delete all events involving the process
    4. Assume every process with that name is malicious

Correct Answer: 1

Explanation:

A familiar process name running from an unexpected location can indicate masquerading or copied tooling. The hunter should compare the file hash, digital signature, path, parent process, command line, and behavior with legitimate instances. Attackers may rename or relocate executables to resemble trusted software. The mismatch between expected and actual execution location is therefore a useful hunting signal that warrants contextual validation.

Question 266.

Which pattern most strongly suggests automated command-and-control activity?

  1. A user opens an approved document
    2. A normal application saves preferences
    3. A scheduled inventory task runs
    4. A process repeatedly communicates with the same uncommon destination at nearly identical intervals

Correct Answer: 4

Explanation:

Repeated communication at consistent intervals can indicate beaconing to command-and-control infrastructure. The hunter should examine the initiating process, timing pattern, destination, DNS activity, and whether the same behavior occurs on other hosts. Legitimate applications can also communicate periodically, so baseline and application context are important. The signal becomes stronger when paired with unusual execution, persistence, or credential-related behavior.

Question 267.

Which event pattern is most relevant when investigating possible account discovery activity?

  1. A browser opens a common website
    2. A scheduled backup completes
    3. A process repeatedly queries local or domain users, groups, and privilege information
    4. A user prints a document

Correct Answer: 3

Explanation:

Repeated enumeration of users, groups, and privileges can indicate reconnaissance or account discovery. Attackers often collect this information to understand available identities and identify privileged accounts. The hunter should examine the responsible process, command line, user context, parent process, and whether other discovery or lateral-movement behavior followed. Legitimate administrators may perform similar actions, so role and timing should also be considered.

Question 268.

Which statement best describes the value of grouping hunting results by file hash?

  1. It proves every matching file is malicious.
    2. It can reveal how widely the same binary appears across hosts and users.
    3. It replaces behavioral analysis entirely.
    4. It is useful only for software inventory.

Correct Answer: 2

Explanation:

Grouping by file hash helps the hunter determine whether the same binary appears on one system or across many endpoints. This can support scoping and reveal distribution patterns. However, a matching hash does not by itself prove maliciousness, and attackers can modify binaries to generate new hashes. Hash-based analysis is most effective when combined with process ancestry, command lines, users, and network behavior.

Question 269.

A hunter observes an Office application spawning mshta.exe followed by outbound network activity. What should be investigated next?

  1. The document source, process chain, command line, network destination, and any created files
    2. Only the Office application version
    3. Printer settings
    4. Screen resolution

Correct Answer: 1

Explanation:

An Office application spawning a trusted scripting-capable utility followed by outbound communication is a suspicious chain that may indicate malicious document execution or abuse of a living-off-the-land binary. The hunter should review the original document, process ancestry, command-line arguments, destination, downloaded or created files, and subsequent execution. The combination of unusual parent-child relationships and network activity provides a strong basis for deeper investigation.

Question 270.

Which behavior most strongly suggests preparation for data exfiltration?

  1. A user opens a standard application
    2. A routine update completes
    3. A browser accesses a common site
    4. A process searches for sensitive documents, gathers them into one folder, and creates a compressed archive

Correct Answer: 4

Explanation:

Searching for sensitive files, collecting them into a staging directory, and compressing them can indicate preparation for exfiltration. The hunter should identify the data gathered, the process responsible, the user involved, the archive location, and whether outbound transfers followed. Legitimate backup, migration, or administrative activity may look similar, so the behavior should be compared with normal business processes before reaching a conclusion.

Question 271.

Which hunting strategy is most effective when adversaries replace their malware binaries frequently but continue using the same persistence method?

  1. Search only file hashes
    2. Search only filenames
    3. Hunt for the recurring persistence behavior and surrounding execution pattern
    4. Ignore persistence telemetry

Correct Answer: 3

Explanation:

File hashes and names can change quickly, while persistence techniques may remain stable across multiple variants. Hunting for the behavior itself, such as recurring startup changes, service creation, or scheduled-task activity, provides broader coverage. The hunter can then correlate those behaviors with process ancestry, users, files, and network activity. Behavioral hunting is therefore more resilient against changing malware artifacts.

Question 272.

Which statement best describes the value of establishing prevalence for a process or command line?

  1. Any low-prevalence item is automatically malicious.
    2. Prevalence helps prioritize unusual activity while still requiring contextual validation.
    3. High-prevalence items can never be malicious.
    4. Prevalence eliminates the need for behavioral analysis.

Correct Answer: 2

Explanation:

Prevalence provides useful context by showing how common or rare a process, command line, or artifact is across the environment. Rare behavior may deserve more attention, but it can still be legitimate. Likewise, common tools can be abused maliciously. Hunters should use prevalence as a prioritization signal and combine it with process relationships, user context, paths, and network activity before making a determination.

Question 273.

A normally inactive account begins authenticating to several critical servers overnight. What should the hunter investigate first?

  1. Source systems, authentication methods, destination servers, timing, and resulting activity
    2. Only the account display name
    3. Printer queues
    4. Desktop wallpaper

Correct Answer: 1

Explanation:

A previously inactive account accessing critical servers during unusual hours is a meaningful anomaly. The hunter should determine where the activity originated, how authentication occurred, which systems were accessed, and what processes or commands followed. Historical account behavior and intended role provide important context. The combination of inactivity, unusual timing, and access to sensitive systems warrants careful investigation.

Question 274.

Which behavior most strongly suggests defense evasion through artifact removal?

  1. A user opens an approved document
    2. A normal update installs
    3. A scheduled backup completes
    4. A process executes suspicious activity and then deletes its files and clears relevant logs

Correct Answer: 4

Explanation:

Deleting files and clearing logs after suspicious execution can indicate an attempt to remove evidence and hinder investigation. The hunter should reconstruct the activity using any remaining endpoint or centralized telemetry, identify the responsible process and account, and examine what occurred before the cleanup. Artifact removal is especially suspicious when it follows credential access, persistence, or network communication.

Question 275.

A suspicious domain appears in DNS activity from multiple hosts. Which action best helps determine whether the behavior is coordinated?

  1. Review only external reputation information
    2. Ignore the processes associated with the queries
    3. Correlate the DNS requests with hosts, users, processes, timestamps, and subsequent connections
    4. Delete the DNS events

Correct Answer: 3

Explanation:

Correlating DNS activity with endpoint telemetry can reveal whether multiple hosts are contacting the same infrastructure through similar processes or users. Timing and subsequent connections may show a coordinated pattern. External reputation data can help prioritize the domain, but local context is essential for determining its role in the environment. The hunter should also consider whether the domain is expected for legitimate software.

Question 276.

Which statement best describes how ATT&CK tactics can help organize hunt findings?

  1. They identify the exact malware family automatically.
    2. They provide high-level objectives that help place observed techniques into an attack progression.
    3. They replace event telemetry.
    4. They prove every mapped event is malicious.

Correct Answer: 2

Explanation:

ATT&CK tactics represent broad adversary objectives such as persistence, credential access, discovery, and lateral movement. Mapping observed techniques to these objectives can help hunters understand where activity fits within a broader intrusion and what behaviors may logically follow. The framework improves organization and communication, but it does not replace evidence from endpoint, identity, or network telemetry.

Question 277.

A hunter discovers an unfamiliar remote-support application installed only on finance systems. What should be investigated first?

  1. Installation source, execution history, users, destinations, authorization status, and whether deployment is expected for those systems
    2. Assume every finance host is compromised immediately
    3. Ignore the application because remote-support software can be legitimate
    4. Delete all host telemetry

Correct Answer: 1

Explanation:

A remote-support tool limited to sensitive systems deserves careful review, especially if it is not part of an approved deployment. The hunter should determine how it was installed, who used it, where it connected, and whether there is a documented business need. Comparing affected hosts and installation times can reveal whether the software was deployed intentionally or introduced through suspicious activity.

Question 278.

Which behavior most strongly suggests privilege escalation?

  1. A standard user opens a browser
    2. An approved application launches normally
    3. A routine maintenance task runs
    4. A user-level process unexpectedly results in execution under a system-level account

Correct Answer: 4

Explanation:

An unexpected transition from user-level execution to a system-level account can indicate exploitation or abuse of an elevation mechanism. The hunter should inspect the process tree, account context, command line, privilege change, and actions performed afterward. Legitimate installers and administrative tools may also elevate privileges, so signer information, deployment context, and historical behavior are important for validation.

Question 279.

Which investigation technique is most useful for determining what happened immediately before a suspicious privilege escalation event?

  1. Reviewing only the final elevated process
    2. Searching only for one filename
    3. Building a timeline that includes preceding process, authentication, file, and system events
    4. Reviewing only installed software

Correct Answer: 3

Explanation:

A timeline can reveal the chain of events leading to privilege escalation, including initial execution, process creation, file changes, account activity, and other precursors. Looking only at the elevated process may miss how the privilege transition occurred. Chronological reconstruction helps the hunter identify the likely cause and connect the escalation to earlier suspicious behavior.

Question 280.

Which action best completes a hunt after the hunter identifies a new malicious behavior that existing detections did not catch?

  1. Delete the hunt results
    2. Document the behavior, establish scope, support response, and create or improve reusable detection logic where appropriate
    3. Disable relevant telemetry
    4. Leave the behavior undocumented

Correct Answer: 2

Explanation:

A hunt that discovers previously undetected malicious behavior should feed improvements back into defensive operations. The hunter should document the evidence, affected systems, users, and timeline, then coordinate any required response. The validated behavior can also be used to improve detections or future hunt analytics. This feedback loop helps turn one successful investigation into broader, repeatable defensive coverage.