CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part19 Q361-380

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 361.

A Falcon Hunter identifies an uncommon executable that appears immediately after a suspicious archive is extracted. What should the hunter investigate first?

  1. The archive source, extracted files, process ancestry, command line, user context, and subsequent activity
    2. Only the executable filename
    3. Printer configuration
    4. Desktop wallpaper settings

Correct Answer: 1

Explanation:

When an uncommon executable appears immediately after archive extraction, the hunter should reconstruct the delivery and execution chain. The archive source, extracted files, process tree, command-line arguments, user context, and any resulting network or file activity can reveal whether the archive delivered malicious content. The filename by itself is weak evidence because attackers can easily rename files. Correlating the surrounding events provides a more reliable basis for determining intent.

Question 362.

Which behavior most strongly suggests persistence through a service configuration change?

  1. A user opens an approved application
    2. A routine update runs
    3. A scheduled inventory task completes
    4. A service is modified to launch an unfamiliar executable automatically

Correct Answer: 4

Explanation:

Modifying a service to launch an unfamiliar executable can provide persistence across reboots or service restarts. The hunter should inspect the process that made the change, the account involved, the new binary path, and subsequent service execution. Legitimate software maintenance can also modify services, so signer information, deployment context, timing, and related host activity should be reviewed before deciding whether the modification is malicious.

Question 363.

Which telemetry is most useful when investigating possible lateral movement involving a privileged identity?

  1. Screen brightness
    2. Printer queues
    3. Source host, destination host, authentication activity, privileged account use, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Lateral movement involving privileged credentials should be investigated by correlating identity and endpoint activity. The hunter should identify where authentication originated, which system was accessed, how the privileged account was used, and what processes or commands followed. This sequence helps distinguish authorized administration from attacker movement. Historical account behavior and expected administrative jump points provide additional context for validating the activity.

Question 364.

Which approach is most effective when a hunter suspects malicious use of a trusted command-line utility?

  1. Treat every execution as malicious
    2. Review the command line, parent process, user, execution path, and follow-on behavior
    3. Ignore the utility because it is signed
    4. Search only for the process name

Correct Answer: 2

Explanation:

Trusted command-line tools can be abused for malicious purposes while appearing legitimate at first glance. The hunter should focus on how the utility was invoked, which arguments were used, who launched it, where it executed from, and what happened afterward. Signed software is not automatically benign in every context. Behavioral analysis is therefore more useful than relying only on the executable’s reputation.

Question 365.

A Falcon Hunter sees a common process executing from an unusual directory on one host. What should the hunter do first?

  1. Compare its path, hash, signer, parent process, command line, and behavior with normal instances
    2. Ignore it because the process name is familiar
    3. Delete all matching events
    4. Assume every process with that name is malicious

Correct Answer: 1

Explanation:

A common process name running from an unexpected path can indicate masquerading or copied tooling. The hunter should compare the executable’s hash, digital signature, path, process ancestry, command line, and related behavior with known legitimate instances. Attackers may deliberately imitate trusted process names. The execution-location mismatch provides a useful hunting signal, but contextual validation is still required.

Question 366.

Which pattern most strongly suggests possible command-and-control beaconing?

  1. A user opens a normal document
    2. A scheduled update runs
    3. A service reads a local configuration file
    4. A process repeatedly contacts the same rare destination at similar intervals over time

Correct Answer: 4

Explanation:

Repeated communication to an uncommon destination at similar intervals can indicate automated beaconing. The hunter should examine the responsible process, timing regularity, DNS activity, destination characteristics, and whether other systems exhibit the same pattern. Legitimate software may also perform periodic communication, so application purpose and historical baseline should be reviewed before concluding that the behavior is malicious.

Question 367.

Which event pattern is most relevant when hunting for host or system discovery?

  1. A browser opens a known website
    2. A normal backup runs
    3. A process repeatedly queries host identity, operating-system details, network configuration, and privileges
    4. A user prints a document

Correct Answer: 3

Explanation:

Repeated collection of host, operating-system, network, and privilege information can indicate system discovery. Attackers often gather this information to understand the environment before choosing later actions. The hunter should inspect the process, command line, parent process, user, timing, and any subsequent credential or lateral-movement activity. Legitimate administrators may perform similar checks, so context remains important.

Question 368.

Which statement best describes the value of grouping search results by process path?

  1. It proves every unusual path is malicious.
    2. It can reveal processes executing from unexpected locations or recurring suspicious directories.
    3. It eliminates the need for command-line review.
    4. It is useful only for software inventory.

Correct Answer: 2

Explanation:

Grouping by process path can expose anomalies such as trusted process names executing from user-writable or temporary directories. It may also reveal repeated use of a suspicious directory across multiple endpoints. The hunter should then review hashes, signers, command lines, users, and parent processes. Path-based grouping is a useful prioritization technique but does not automatically determine maliciousness.

Question 369.

A hunter observes a browser launching a scripting engine that creates and executes a file from a temporary directory. What should be investigated next?

  1. The browser activity, process chain, command line, created file, source, and follow-on behavior
    2. Only the browser version
    3. Printer settings
    4. Screen resolution

Correct Answer: 1

Explanation:

A browser spawning a scripting engine that creates and executes a temporary file can indicate exploitation, malicious download activity, or social engineering. The hunter should reconstruct the process sequence, inspect command-line arguments, identify the file source and hash, and review subsequent process or network activity. The complete chain provides more meaningful evidence than examining any individual event alone.

Question 370.

Which behavior most strongly suggests preparation for data exfiltration?

  1. A user opens a standard application
    2. A normal service writes a small log file
    3. A routine update completes
    4. A process searches for sensitive files, gathers them into one folder, and compresses them into an archive

Correct Answer: 4

Explanation:

Searching for sensitive information, consolidating files, and compressing them can indicate data staging before exfiltration. The hunter should identify which files were collected, which process and user performed the activity, where the archive was stored, and whether unusual outbound communication followed. Legitimate backup or migration tools can create similar patterns, so normal business activity should be considered during validation.

Question 371.

Which hunting strategy is most effective when attackers frequently change binaries but keep using the same discovery and persistence methods?

  1. Search only exact hashes
    2. Search only filenames
    3. Hunt for recurring behaviors, process relationships, and technique sequences
    4. Ignore process telemetry

Correct Answer: 3

Explanation:

Behavioral hunting remains effective even when attackers modify files because discovery commands, persistence methods, and execution relationships may stay consistent. Hunters can focus on recurring techniques and sequences rather than relying entirely on file hashes or names. Static indicators are still valuable for immediate scoping, but behavioral analytics provide broader coverage against changing tool variants.

Question 372.

Which statement best describes the value of baselining process paths and command lines?

  1. It proves all common values are legitimate.
    2. It helps identify deviations from normal execution patterns that may deserve deeper investigation.
    3. It removes the need for manual analysis.
    4. It automatically blocks every uncommon process.

Correct Answer: 2

Explanation:

Baselining process paths and command lines helps hunters understand how software normally executes in the environment. A familiar executable running from a new directory or using unusual arguments can become a high-value investigative lead. These deviations are not automatically malicious, so user context, process ancestry, signer information, and related activity should also be reviewed.

Question 373.

A privileged account that normally uses an administrative jump host begins authenticating directly from a user workstation. What should the hunter investigate first?

  1. Source workstation, authentication method, destinations, timing, and resulting privileged actions
    2. Only the account display name
    3. Printer history
    4. Desktop theme

Correct Answer: 1

Explanation:

Privileged authentication from an unexpected workstation can indicate credential theft, policy bypass, or an authorized exception. The hunter should inspect the source workstation, authentication method, target systems, timing, and actions performed after login. Historical behavior and administrative policy provide useful context. The source host should also be examined for credential-access or other suspicious activity.

Question 374.

Which behavior most strongly suggests defense evasion through log manipulation?

  1. A user opens a normal application
    2. A scheduled maintenance task runs
    3. A routine backup completes
    4. A process performs suspicious activity and then clears or removes relevant logs

Correct Answer: 4

Explanation:

Clearing logs after suspicious activity can indicate an attempt to conceal evidence and hinder investigation. The hunter should identify the responsible process and user, reconstruct what happened before the cleanup, and look for related telemetry stored centrally or elsewhere. Log manipulation becomes even more significant when paired with security-control changes, persistence, or credential-access behavior.

Question 375.

A suspicious domain is observed in DNS activity from multiple systems, but the frequency differs greatly between hosts. What should the hunter do?

  1. Assume every host is equally compromised
    2. Ignore systems with low request counts
    3. Compare requesting processes, users, timestamps, frequency, and subsequent network connections across the hosts
    4. Delete the DNS events

Correct Answer: 3

Explanation:

Different request frequencies can reflect different software behavior, stages of activity, or unrelated causes. The hunter should compare which processes made the queries, which users were active, how often requests occurred, and whether connections followed. This context helps determine whether the systems are part of the same suspicious pattern or whether some activity is benign.

Question 376.

Which statement best describes how ATT&CK can help prioritize additional hunting?

  1. It automatically identifies the attacker.
    2. Observed techniques can suggest related tactics and behaviors that may logically occur before or after them.
    3. It replaces endpoint telemetry.
    4. It proves every mapped event is malicious.

Correct Answer: 2

Explanation:

ATT&CK can help hunters reason about likely attack progression. If a technique associated with credential access is observed, the hunter may prioritize searches for privilege escalation or lateral movement. The framework provides a structured way to expand the investigation, but local telemetry and environmental context are still required to determine whether related behavior actually occurred.

Question 377.

A hunter finds an approved remote-access tool installed on a server where it has never been used before. What should be investigated first?

  1. Installation source, executing user, command line, destinations, and whether the use is authorized for that server
    2. Ignore it because the software is approved somewhere in the organization
    3. Assume all instances of the tool are malicious
    4. Delete the server’s telemetry

Correct Answer: 1

Explanation:

Approved software can still be suspicious when it appears on unexpected assets. The hunter should determine how the tool was installed, who used it, what commands or sessions were initiated, and which destinations it contacted. Asset role and authorization scope matter. Unexpected deployment of legitimate remote-access software can indicate misuse or unauthorized access.

Question 378.

Which behavior most strongly suggests possible privilege escalation?

  1. A user opens an approved browser
    2. A normal application starts
    3. A scheduled inventory task runs
    4. A standard-user process unexpectedly launches a system-level child process

Correct Answer: 4

Explanation:

An unexpected transition from standard-user execution to system-level privileges can indicate exploitation or abuse of an elevation mechanism. The hunter should examine the process tree, user context, command-line arguments, elevation path, and subsequent actions. Legitimate installers can also perform privileged execution, so software context and known administrative activity should be included in the analysis.

Question 379.

Which investigation technique is most useful when determining whether suspicious discovery and authentication events are connected?

  1. Review only the discovery event
    2. Search only the username
    3. Correlate discovery, authentication, process, and network events chronologically
    4. Review only asset inventory

Correct Answer: 3

Explanation:

Chronological correlation helps show whether discovery activity was followed by authentication to systems identified during reconnaissance. Adding process and network events can reveal whether those authentications led to remote execution or further attacker activity. A timeline makes it easier to determine whether individual events form one attack chain rather than unrelated occurrences.

Question 380.

Which action best completes a hunt after a new malicious behavior has been confirmed across several systems?

  1. Delete the investigation results
    2. Document the findings, establish scope, coordinate response, and create or improve reusable detection and hunting logic
    3. Disable the related telemetry
    4. Leave the behavior undocumented

Correct Answer: 2

Explanation:

A confirmed behavior affecting several systems should lead to both response and defensive improvement. The hunter should document affected hosts, users, timelines, indicators, and behavioral evidence, then coordinate containment or remediation. Validated search logic can be converted into reusable detections or hunt analytics, helping the organization identify similar activity more quickly in the future.