CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part15 Q281-300

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 281.

A Falcon Hunter discovers a process that launches from an uncommon directory and creates a network connection immediately afterward. What should the hunter investigate first?

  1. The process ancestry, command line, file hash, user context, and network destination
    2. Only the process filename
    3. Printer configuration
    4. The endpoint’s desktop theme

Correct Answer: 1

Explanation:

A process executing from an uncommon directory and establishing a network connection can indicate malicious activity, but the surrounding context is essential. The hunter should review the parent process, command line, file hash, user identity, path, and destination. This helps determine whether the behavior represents legitimate software, a downloaded tool, or attacker activity. A filename or location alone is not enough to establish malicious intent.

Question 282.

Which behavior most strongly suggests persistence through a scheduled execution mechanism?

  1. A user opens an approved browser
    2. A normal software update completes
    3. A routine backup runs
    4. A newly created scheduled task repeatedly launches an unfamiliar script

Correct Answer: 4

Explanation:

Scheduled tasks can provide persistence by launching code automatically at defined times or events. An unfamiliar script executed by a newly created task deserves investigation. The hunter should identify the task creator, account, command line, script path, creation time, and subsequent executions. Legitimate software also uses scheduled tasks, so deployment context, rarity, and surrounding behavior should be reviewed before classifying the activity.

Question 283.

Which telemetry is most useful when investigating possible lateral movement using remote administration?

  1. Screen brightness
    2. Printer history
    3. Source host, destination host, account used, authentication activity, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Lateral movement investigations require correlation between identity and endpoint activity. The hunter should determine where the connection originated, which account was used, which system was accessed, and what process or command executed afterward. This sequence helps distinguish legitimate administrative access from adversary movement. Authentication data alone may not show what happened after the session was established.

Question 284.

Which approach is most effective when investigating suspicious use of certutil.exe or another legitimate system utility?

  1. Treat every execution as malicious
    2. Analyze command-line arguments, parent process, user, file activity, and network behavior
    3. Ignore it because the binary is signed
    4. Search only for the process name

Correct Answer: 2

Explanation:

Legitimate system utilities can be abused by attackers for activities such as file handling, network retrieval, or execution support. The hunter should focus on how the tool is used, which arguments are supplied, which process launched it, and what files or network events follow. Signed software does not guarantee benign use. Behavioral context provides much stronger evidence than the executable name alone.

Question 285.

A Falcon Hunter identifies an executable that has the same name as a common system process but runs from an unexpected directory. What should the hunter do?

  1. Compare its path, hash, signer, parent process, command line, and behavior with legitimate instances
    2. Ignore it because the name is familiar
    3. Delete all events involving that filename
    4. Assume every process with the same name is malicious

Correct Answer: 1

Explanation:

A familiar process name running from an unusual path may indicate masquerading. The hunter should compare the file’s hash, digital signature, path, process ancestry, and behavior with known legitimate instances. Attackers may choose filenames that resemble trusted software to reduce suspicion. The combination of location mismatch and unusual activity is a useful hunting signal that should be validated carefully.

Question 286.

Which pattern most strongly suggests possible beaconing?

  1. A user opens an approved document
    2. A normal application reads a local file
    3. A scheduled inventory task runs
    4. A process repeatedly contacts the same uncommon destination at similar intervals

Correct Answer: 4

Explanation:

Repeated outbound communication at consistent intervals can indicate command-and-control beaconing. The hunter should inspect the initiating process, destination, timing pattern, DNS activity, and whether the behavior appears on multiple hosts. Legitimate applications can also communicate periodically, so the process purpose and baseline behavior should be considered before concluding that the activity is malicious.

Question 287.

Which event pattern is most relevant when hunting for system or network discovery activity?

  1. A normal browser session
    2. A standard application update
    3. A process repeatedly queries system, network, account, and configuration information
    4. A user prints a document

Correct Answer: 3

Explanation:

Repeated enumeration of system, network, account, and configuration information can indicate discovery activity. Attackers often gather this information to understand the environment before moving laterally or escalating privileges. The hunter should examine the process, command line, user context, parent process, and related follow-on behavior. Legitimate administrators may perform similar queries, so business context and timing should be considered.

Question 288.

Which statement best describes the value of grouping hunting results by user?

  1. It proves the user is compromised.
    2. It can reveal accounts associated with unusual amounts or types of suspicious activity.
    3. It replaces host-level analysis.
    4. It is useful only for access reviews.

Correct Answer: 2

Explanation:

Grouping events by user can help identify identities that appear repeatedly in suspicious activity. A user associated with unusual processes, new hosts, or unexpected remote connections may deserve deeper investigation. Aggregation helps prioritize analysis, but it does not prove compromise. The hunter should still review the account’s role, historical behavior, authentication context, and the detailed events involved.

Question 289.

A hunter observes a browser spawning a script interpreter that downloads and runs another file. What should be investigated next?

  1. The browser activity, process chain, command line, downloaded file, network destination, and subsequent execution
    2. Only the browser version
    3. Printer settings
    4. Screen resolution

Correct Answer: 1

Explanation:

A browser launching a script interpreter that downloads and executes a file is a suspicious chain that may indicate exploitation or social engineering. The hunter should reconstruct the complete process sequence, review the command line, identify the downloaded file and source, and inspect subsequent network or process activity. The chain provides much stronger investigative context than any single event in isolation.

Question 290.

Which behavior most strongly suggests preparation for exfiltration?

  1. A user opens a local application
    2. A normal update installs
    3. A routine service writes a log file
    4. A process locates sensitive files, copies them into a staging directory, and compresses them

Correct Answer: 4

Explanation:

Locating sensitive files, consolidating them in one directory, and compressing them can indicate data staging before exfiltration. The hunter should identify which files were collected, who initiated the activity, which process performed it, and whether unusual outbound transfers followed. Legitimate backup or migration activities can resemble this behavior, so comparison with normal business processes is necessary.

Question 291.

Which hunting approach is most resilient when an adversary changes IP addresses, domains, filenames, and hashes frequently?

  1. Search only known hashes
    2. Search only known domains
    3. Hunt for recurring behavioral patterns, process relationships, and sequences of activity
    4. Ignore endpoint telemetry

Correct Answer: 3

Explanation:

Static indicators can change quickly, while behavioral patterns often remain more stable. Process ancestry, command structures, persistence methods, credential behaviors, and communication patterns can therefore provide more durable detection coverage. Hashes, domains, and IP addresses are still useful for scoping known activity, but behavioral hunting is better suited to identifying related variants that use different indicators.

Question 292.

Which statement best describes the value of baselining network destinations for a server?

  1. It proves every common destination is safe.
    2. It helps identify new or unusual destinations that differ from the server’s normal communication pattern.
    3. It eliminates the need for investigation.
    4. It automatically blocks rare connections.

Correct Answer: 2

Explanation:

Servers often communicate with a predictable set of services and destinations. Establishing a baseline makes unusual external connections easier to identify and prioritize. A new destination is not automatically malicious, and a common destination can still be abused, so the baseline should guide investigation rather than replace it. Process context and timing help determine whether the communication is expected.

Question 293.

A privileged account begins authenticating to several endpoints during unusual hours. What should the hunter investigate first?

  1. Source systems, authentication methods, destination hosts, timing, and resulting privileged activity
    2. Only the account display name
    3. Printer queues
    4. Desktop background

Correct Answer: 1

Explanation:

Unexpected privileged authentication during unusual hours can indicate account compromise or unauthorized use. The hunter should determine where the activity originated, how authentication occurred, which systems were accessed, and what actions followed. Historical behavior and the user’s role provide important context. Because privileged accounts can have significant impact, deviations from normal usage should receive careful scrutiny.

Question 294.

Which behavior most strongly suggests defense evasion through security-control impairment?

  1. A user opens an approved application
    2. A scheduled backup completes
    3. A normal update runs
    4. A process stops security services, modifies exclusions, and disables logging

Correct Answer: 4

Explanation:

Stopping security services, changing exclusions, and disabling logging can reduce monitoring and detection capability. When these actions occur together, they strongly suggest an attempt to impair defenses. The hunter should inspect the responsible process, user, command line, parent process, and subsequent activity. Centralized or remote telemetry can be especially important when local logging has been affected.

Question 295.

A suspicious external domain appears in activity from multiple hosts. Which action best establishes whether the behavior is related?

  1. Review only external reputation information
    2. Ignore which processes contacted the domain
    3. Correlate hosts, users, processes, DNS activity, timestamps, and subsequent connections
    4. Delete the matching events

Correct Answer: 3

Explanation:

Correlating the domain with endpoint and DNS telemetry helps determine whether multiple systems are participating in the same behavior. Similar initiating processes, users, timing, or connection patterns can suggest coordinated activity. Reputation data can provide useful context, but local telemetry is necessary to establish how the domain is actually being used inside the environment.

Question 296.

Which statement best describes the role of ATT&CK techniques during threat hunting?

  1. They automatically identify the exact attacker.
    2. They help categorize observed behaviors and suggest related actions that may be worth investigating.
    3. They replace event telemetry.
    4. They prove every mapped event is malicious.

Correct Answer: 2

Explanation:

ATT&CK techniques provide a consistent framework for describing adversary behavior. Hunters can map observed events to techniques and use those mappings to think about likely preceding or follow-on activity. For example, discovery behavior may lead to hunting for credential access or lateral movement. ATT&CK helps structure the investigation but does not replace evidence from the environment.

Question 297.

A hunter finds an unapproved remote-management tool installed on several servers. What should be done first?

  1. Investigate installation source, execution history, users, remote destinations, and whether the deployment is authorized
    2. Assume every server is compromised immediately
    3. Ignore the software because remote-management tools can be legitimate
    4. Delete all logs

Correct Answer: 1

Explanation:

Unapproved remote-management software may represent shadow IT, legitimate troubleshooting, or attacker-controlled access. The hunter should identify how it was installed, which accounts used it, which systems or external destinations it contacted, and whether there is a documented business purpose. Comparing installation times and affected hosts can help determine whether the tool was deployed intentionally or introduced suspiciously.

Question 298.

Which behavior most strongly suggests privilege escalation?

  1. A user opens a browser normally
    2. A standard maintenance task runs
    3. An approved application starts
    4. A standard-user process unexpectedly results in execution with system-level privileges

Correct Answer: 4

Explanation:

An unexpected transition from standard-user execution to system-level privileges can indicate exploitation or abuse of an elevation mechanism. The hunter should examine process ancestry, user context, command lines, the elevation path, and actions performed afterward. Legitimate software installation may also elevate privileges, so signer information and known administrative activity should be considered when validating the event.

Question 299.

Which investigation technique is most useful for connecting discovery, credential access, and lateral movement into one coherent sequence?

  1. Reviewing only the most severe detection
    2. Searching only a single process name
    3. Building a chronological timeline across process, authentication, file, and network events
    4. Reviewing only host inventory

Correct Answer: 3

Explanation:

A chronological timeline can connect seemingly separate behaviors into a broader intrusion sequence. It can show when discovery occurred, when credentials may have been accessed, and when those credentials were used for remote activity. Temporal correlation helps distinguish related events from coincidence and can expose additional stages of the attack that were not originally detected.

Question 300.

Which action best completes a hunt after the hunter validates a previously undetected malicious behavior?

  1. Delete the investigation results
    2. Document the findings, determine scope, support response, and convert the validated behavior into reusable detection or hunting logic where appropriate
    3. Disable relevant telemetry
    4. Leave the findings undocumented

Correct Answer: 2

Explanation:

Validated hunting findings should strengthen both immediate response and future defenses. The hunter should document affected systems, users, timelines, indicators, and behavior, then coordinate containment or remediation as needed. Useful searches or analytics can be converted into reusable detection logic. This feedback loop helps ensure that behavior discovered manually can be identified more efficiently if it appears again.