CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part11 Q201-220

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 201.

A Falcon Hunter sees a suspicious process launch from a user profile directory and immediately spawn a command shell. What should the hunter investigate first?

  1. The process tree, command line, file hash, user context, and any related file or network activity
    2. Only the hostname
    3. The user’s printer configuration
    4. The endpoint’s desktop background

Correct Answer: 1

Explanation:

A suspicious process launching from a user profile directory and spawning a command shell may indicate downloaded malware, script execution, or another user-level execution technique. The hunter should examine the parent-child process chain, command-line arguments, file hash, user identity, and related network or file events. Looking at the full context helps distinguish malicious activity from legitimate software behavior. The path or filename alone is not sufficient to determine intent.

Question 202.

Which behavior most strongly suggests persistence through a newly created service?

  1. A browser opens a normal website
    2. A routine application update completes
    3. A scheduled inventory job runs
    4. A suspicious process creates a service configured to launch an unfamiliar executable at startup

Correct Answer: 4

Explanation:

A newly created service that launches an unfamiliar executable at startup can provide persistence across reboots. The hunter should inspect the service creation event, the process responsible, the configured binary path, the account used, and subsequent executions. Legitimate software installers can also create services, so signer information, timing, deployment context, and related activity should be evaluated before deciding whether the event is malicious.

Question 203.

Which telemetry is most useful for investigating suspected lateral movement using remote administration?

  1. Screen resolution settings
    2. Printer status
    3. Source host, destination host, account used, authentication events, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Lateral movement investigations benefit from correlating authentication events with endpoint activity. The hunter should identify where the connection originated, which account was used, which system was accessed, and what process or command executed afterward. This helps distinguish legitimate administrative activity from malicious movement. Authentication alone may show that access occurred, but it does not reveal what the user or attacker did after reaching the destination.

Question 204.

Which approach is most effective when hunting for suspicious use of a legitimate administrative utility?

  1. Treat all use of the utility as malicious
    2. Evaluate parent process, command line, user, source host, destination, and follow-on behavior
    3. Ignore the utility because it is signed
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Attackers often abuse legitimate administrative tools because those utilities are already trusted and present in the environment. The hunter should focus on how the tool was used rather than whether the binary itself is legitimate. Unusual command-line arguments, source systems, users, destinations, or child processes can reveal misuse. Signed or trusted software can still participate in malicious activity.

Question 205.

A Falcon Hunter sees a process that is very common across the environment but appears with an unusual parent process on one endpoint. What should the hunter do?

  1. Investigate the parent-child relationship, command line, user, and surrounding activity
    2. Ignore it because the executable is common
    3. Delete all related events
    4. Assume all instances of the process are malicious

Correct Answer: 1

Explanation:

A common process can still be used maliciously when launched in an unusual context. Parent-child relationships are valuable because they reveal how execution started. The hunter should examine the parent, command-line arguments, user context, file path, and any follow-on network or file activity. Behavioral anomalies can be more meaningful than the prevalence of the executable itself.

Question 206.

Which pattern most strongly suggests possible command-and-control beaconing?

  1. A user opens an approved spreadsheet
    2. A scheduled patch installs
    3. A process performs one legitimate update check
    4. A process repeatedly contacts the same rare external destination at similar time intervals

Correct Answer: 4

Explanation:

Regularly repeated outbound connections to a rare destination can indicate command-and-control beaconing. The hunter should examine the initiating process, connection intervals, destination, affected hosts, and any related DNS activity. Legitimate software can also create periodic connections, so baseline behavior and process purpose should be considered. Beaconing becomes more suspicious when paired with unusual process execution or persistence.

Question 207.

Which event pattern is most relevant when investigating possible credential theft followed by lateral movement?

  1. A normal application launch
    2. A routine inventory scan
    3. Suspicious credential-access behavior followed by unusual remote authentication to other hosts
    4. A user printing a document

Correct Answer: 3

Explanation:

Credential access becomes especially important when it is followed by unusual remote authentication. This sequence can indicate that an attacker obtained credentials and then reused them for lateral movement. The hunter should inspect the process responsible for credential access, affected accounts, source and destination systems, and resulting process activity. Correlation between endpoint and identity telemetry helps establish the full sequence.

Question 208.

Which statement best describes the value of grouping hunting results by process name and command line?

  1. It confirms every matching process is malicious.
    2. It helps reveal recurring patterns, unusual command variants, and outliers across hosts.
    3. It removes the need to inspect individual events.
    4. It is useful only for software inventory.

Correct Answer: 2

Explanation:

Grouping by process and command line can reveal how frequently a behavior occurs and whether unusual variants stand out. For example, one rare command line may appear only on compromised hosts while normal instances use different arguments. Aggregation helps prioritize investigation, but the hunter should still review underlying events for user context, timing, parent processes, and network activity.

Question 209.

A hunter observes a document application launching PowerShell, which then creates an executable in a temporary directory. What is the best next step?

  1. Investigate the document source, process chain, command line, created file, and subsequent execution
    2. Assume the sequence is normal office behavior
    3. Ignore PowerShell because it is built into Windows
    4. Delete the events immediately

Correct Answer: 1

Explanation:

A document application spawning PowerShell and creating an executable is a suspicious chain that can indicate malicious document execution or scripting. The hunter should inspect the original document, process ancestry, command-line parameters, created file hash, location, and any follow-on execution or network activity. The full sequence provides more meaningful context than any individual event alone.

Question 210.

Which behavior most strongly suggests data staging before exfiltration?

  1. A standard application writes a configuration file
    2. A browser opens a routine website
    3. A normal update downloads
    4. A process collects many files, places them in one directory, and compresses them into a large archive

Correct Answer: 4

Explanation:

Attackers often stage data by collecting files into a central location and compressing them before transfer. The hunter should examine the source files, responsible process, user context, archive path, and whether unusual outbound network activity followed. Backup or synchronization tools may generate similar behavior, so the sequence should be compared against known baseline activity and expected business processes.

Question 211.

Which hunting strategy is most effective when attackers change filenames and hashes but keep using the same attack workflow?

  1. Search only exact hashes
    2. Search only filenames
    3. Hunt for recurring behavioral patterns, process ancestry, and activity sequences
    4. Ignore command-line telemetry

Correct Answer: 3

Explanation:

Behavioral hunting is more resilient because attackers can easily change filenames and file hashes. Process ancestry, command patterns, persistence methods, credential behavior, and network sequences may remain consistent. Static indicators remain useful for immediate scoping, but behavioral patterns can continue detecting related activity after superficial artifacts change.

Question 212.

Which statement best describes the purpose of baselining service-account behavior?

  1. It proves all normal activity is safe.
    2. It helps identify deviations from expected systems, times, and operations for the account.
    3. It eliminates the need for investigation.
    4. It automatically blocks unusual access.

Correct Answer: 2

Explanation:

Service accounts often perform predictable automated tasks, which makes unusual behavior easier to identify. A service account that suddenly logs on interactively, accesses new systems, or launches unexpected processes may warrant investigation. Baselining helps prioritize these deviations, but it does not automatically classify them as malicious. Context and business purpose must still be considered.

Question 213.

A service account begins authenticating to several workstations instead of its normal application servers. What should the hunter investigate first?

  1. Source systems, authentication type, destinations, timing, and resulting activity
    2. Only the account name
    3. Printer history
    4. Display settings

Correct Answer: 1

Explanation:

A service account accessing systems outside its normal pattern can indicate credential compromise or misuse. The hunter should determine where the activity originated, how authentication occurred, which hosts were accessed, and what processes or commands followed. Because service accounts usually have stable behavior, deviations are especially valuable hunting signals. The account’s assigned purpose should be compared with the observed activity.

Question 214.

Which behavior most strongly suggests defense evasion?

  1. A user launches an approved application
    2. A routine patch installs
    3. A scheduled scan runs normally
    4. A process stops security services, modifies exclusions, and removes local evidence

Correct Answer: 4

Explanation:

Stopping security services, changing exclusions, and removing evidence are all defense-evasion behaviors. When they occur together, they strongly suggest an attempt to reduce visibility or hinder investigation. The hunter should identify the responsible process, account, commands, parent process, and subsequent activity. Centralized telemetry may be particularly valuable if local logs or artifacts were altered.

Question 215.

A suspicious domain appears on several endpoints. Which approach best determines its significance?

  1. Review only external reputation
    2. Ignore the processes that contacted it
    3. Correlate the domain with hosts, processes, users, DNS activity, and timestamps
    4. Delete the matching events

Correct Answer: 3

Explanation:

Correlating the domain with enterprise telemetry helps the hunter determine how widely it appears and which processes or users are associated with it. The same domain may be used differently across systems, so local context is important. External reputation can add useful information, but it should not replace investigation of the actual endpoint and network behavior.

Question 216.

Which statement best describes how MITRE ATT&CK should be used during a hunt?

  1. It should replace Falcon telemetry.
    2. It provides a structured way to categorize observed behavior and identify related techniques worth investigating.
    3. It guarantees that any mapped behavior is malicious.
    4. It is useful only for post-incident reporting.

Correct Answer: 2

Explanation:

MITRE ATT&CK helps hunters organize observed behavior into tactics and techniques. This can suggest related activity that should be investigated next. For example, evidence of credential access may lead to additional searches for lateral movement or persistence. ATT&CK provides a common framework, but conclusions still depend on endpoint telemetry, context, and evidence from the environment.

Question 217.

A hunter discovers an unapproved remote-control tool on multiple endpoints. What should the hunter do first?

  1. Investigate installation source, execution history, users, network destinations, and whether the tool is authorized
    2. Assume every endpoint is compromised immediately
    3. Ignore the tool because remote-control software can be legitimate
    4. Delete all endpoint logs

Correct Answer: 1

Explanation:

Remote-control tools can be legitimate support software or attacker persistence mechanisms. The hunter should determine how the tool was installed, who executed it, which systems or external destinations it contacted, and whether it matches approved business use. Comparing affected hosts can reveal a common installer, account, or destination. Context should guide classification rather than the software category alone.

Question 218.

Which behavior most strongly suggests privilege escalation?

  1. A user launches a browser normally
    2. A scheduled backup completes
    3. An approved application opens
    4. A low-privilege process unexpectedly launches a process running under a system-level context

Correct Answer: 4

Explanation:

An unexpected transition from low privilege to system-level execution can indicate exploitation or abuse of an elevation mechanism. The hunter should inspect the process tree, user identity, command line, elevation path, and any actions performed afterward. Legitimate installers and administrative workflows may also elevate processes, so signer information and historical behavior should be considered during analysis.

Question 219.

Which investigation technique is most useful for understanding how a suspicious event developed into a broader compromise?

  1. Reviewing only the detection title
    2. Searching only one filename
    3. Building a chronological timeline of process, file, network, and authentication events
    4. Reviewing only installed applications

Correct Answer: 3

Explanation:

A chronological timeline helps connect isolated events into a coherent sequence. It can reveal initial execution, persistence, credential access, remote activity, command-and-control communication, and other follow-on behaviors. Individual alerts may show only one stage of an intrusion. Timelining can expose relationships and actions that were not obvious from the original detection.

Question 220.

Which action best completes a threat hunt after malicious behavior has been confirmed?

  1. Delete the investigation notes
    2. Document findings, determine scope, support response, and convert useful hunting logic into reusable detections or future hunts
    3. Disable relevant telemetry
    4. Leave the findings undocumented

Correct Answer: 2

Explanation:

A successful hunt should improve both the immediate response and future defensive capability. Hunters should document affected hosts, users, timelines, indicators, and behavior, then coordinate containment and remediation where necessary. Useful search logic can be transformed into reusable detections or analytics. Lessons learned can also reveal telemetry gaps and generate stronger hypotheses for future hunts.