CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part13 Q241-260

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 241.

A Falcon Hunter identifies an unusual process that launches from a user-writable directory and immediately creates a child command shell. What should the hunter investigate first?

  1. The process tree, command line, file hash, user context, and related network or file activity
    2. Only the executable filename
    3. Printer configuration
    4. Desktop theme settings

Correct Answer: 1

Explanation:

Execution from a user-writable location followed by a command shell can indicate malicious staging, script execution, or legitimate software behavior. The hunter should reconstruct the process chain and review the file hash, command-line arguments, user identity, created files, and outbound activity. The path and filename alone are not enough to determine intent. Multiple contextual indicators provide a stronger basis for deciding whether deeper response is required.

Question 242.

Which behavior most strongly suggests persistence through modification of a startup mechanism?

  1. A browser opens normally
    2. A routine update completes
    3. A standard inventory task executes
    4. An unknown executable is added to a location that causes it to launch automatically at logon

Correct Answer: 4

Explanation:

Adding an unfamiliar executable to an automatic startup location can provide persistence across user sessions. The hunter should determine which process made the change, the associated user, the executable path, and whether the file appears on other endpoints. Legitimate applications also create startup entries, so timing, signer information, rarity, and related activity should be used to distinguish benign from suspicious behavior.

Question 243.

Which telemetry is most useful when investigating suspected lateral movement through remote execution?

  1. Screen resolution
    2. Printer queues
    3. Source host, destination host, authentication activity, account used, and resulting process creation
    4. Installed fonts

Correct Answer: 3

Explanation:

Remote execution typically involves a combination of authentication and endpoint activity. The hunter should identify where the action originated, which account was used, which system was targeted, and what process launched on the destination. This makes it easier to distinguish expected administration from malicious movement. Looking at authentication alone may not reveal what happened after the connection was established.

Question 244.

Which approach is most effective when investigating suspicious use of a trusted system utility?

  1. Treat all execution of the utility as malicious
    2. Review parent process, command line, user, path, and follow-on activity
    3. Ignore it because the binary is trusted
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Trusted system utilities are frequently abused by attackers because they may blend into normal activity. The hunter should evaluate how the tool was launched, which arguments were supplied, who ran it, where it executed from, and what actions followed. A trusted executable can still perform malicious operations. Behavioral context is therefore more useful than relying solely on reputation or digital signatures.

Question 245.

A Falcon Hunter discovers a process that is common across the enterprise but uses a unique command line on one server. What should the hunter do?

  1. Investigate the unusual command line, parent process, user, and related activity
    2. Ignore it because the process is common
    3. Delete all events involving the process
    4. Assume every instance is malicious

Correct Answer: 1

Explanation:

Common processes can still be abused. The distinguishing feature may be an unusual command line, unexpected parent process, rare user, or suspicious destination. The hunter should compare the server’s behavior with normal instances across the environment. Behavioral deviations often reveal malicious use that would be missed if the executable were trusted simply because it is common.

Question 246.

Which pattern most strongly suggests command-and-control beaconing?

  1. A user opens a local application
    2. A scheduled task runs once
    3. A system performs a normal update check
    4. A process makes repeated outbound connections to the same rare destination at regular intervals

Correct Answer: 4

Explanation:

Periodic outbound communication to an uncommon destination is a classic hunting signal for possible beaconing. The hunter should inspect the process responsible, the destination, timing pattern, DNS activity, and whether the behavior occurs on multiple hosts. Legitimate software may also communicate on a schedule, so process purpose and historical baseline should be used to validate the hypothesis.

Question 247.

Which event pattern is most relevant when hunting for credential theft followed by account misuse?

  1. A standard application starts
    2. A normal backup runs
    3. Suspicious access to credential-related resources followed by unusual authentication activity
    4. A user prints a document

Correct Answer: 3

Explanation:

Credential-access behavior becomes more significant when followed by anomalous logons or remote access. The hunter should connect the process responsible for accessing credentials with any new authentication activity, source systems, destination hosts, and resulting processes. This can reveal whether credentials were successfully obtained and reused. Correlating endpoint and identity telemetry is essential for understanding the sequence.

Question 248.

Which statement best describes the value of grouping search results by destination IP or domain?

  1. It proves all rare destinations are malicious.
    2. It can reveal shared infrastructure, outliers, and clusters of affected hosts.
    3. It replaces process analysis.
    4. It is useful only for asset inventory.

Correct Answer: 2

Explanation:

Grouping by destination helps hunters identify which external systems are contacted most often and which are rare or associated with multiple suspicious hosts. This can reveal shared command-and-control infrastructure or suspicious clusters. Hunters should then pivot into the responsible processes, users, timestamps, and DNS activity. Rarity alone is not enough to confirm maliciousness.

Question 249.

A hunter observes an email client launching PowerShell, which then creates an executable and starts it. What should be investigated next?

  1. The message or attachment source, process chain, command line, created file, and subsequent activity
    2. Only the user’s email address
    3. The endpoint’s printer status
    4. Screen brightness

Correct Answer: 1

Explanation:

An email client spawning PowerShell and creating an executable is a suspicious sequence that may indicate malicious attachment execution or exploitation. The hunter should examine the message or attachment, process ancestry, PowerShell command line, file hash, execution path, and any network connections. The full chain helps determine how execution began and whether the same technique appears elsewhere.

Question 250.

Which behavior most strongly suggests data staging before exfiltration?

  1. A user opens a browser
    2. A normal application creates a cache file
    3. A scheduled update installs
    4. A process gathers many files, copies them to a staging folder, and compresses them into an archive

Correct Answer: 4

Explanation:

Attackers often gather files into one location and compress them before transferring data externally. The hunter should determine which files were collected, the process responsible, the user context, archive location, and whether network transfer followed. Legitimate backup or archival activity can look similar, so business context and baseline behavior should be considered.

Question 251.

Which hunting strategy is most effective when attackers frequently change file hashes but preserve the same execution behavior?

  1. Search only exact hashes
    2. Search only filenames
    3. Use behavioral hunting based on process relationships, command lines, and activity sequences
    4. Ignore endpoint process data

Correct Answer: 3

Explanation:

Hashes can change with even small modifications to a file, making them fragile long-term indicators. Process ancestry, command syntax, persistence patterns, and activity sequences often remain more consistent across variants. Behavioral hunting therefore provides broader coverage against changing tools. Static indicators are still valuable for rapid scoping, but they should be combined with behavioral analytics.

Question 252.

Which statement best describes the purpose of baselining administrative activity?

  1. It proves all common administrator actions are safe.
    2. It helps identify unusual hosts, times, tools, or commands used by administrators.
    3. It removes the need for investigation.
    4. It automatically blocks uncommon behavior.

Correct Answer: 2

Explanation:

Administrative accounts often perform recurring tasks on predictable systems. Establishing a baseline helps the hunter identify deviations, such as an administrator using a new tool, authenticating from an unusual workstation, or accessing unexpected servers. Deviations are not automatically malicious, but they provide useful leads. Baselines should be combined with process, authentication, and network context.

Question 253.

A privileged account suddenly authenticates from a workstation it has never used before. What should the hunter investigate first?

  1. Source system, authentication method, destination systems, timing, and resulting privileged activity
    2. Only the account display name
    3. Printer history
    4. Desktop theme

Correct Answer: 1

Explanation:

A privileged account authenticating from a new workstation is a meaningful anomaly. The hunter should determine how the account authenticated, what systems it accessed, what privileged actions followed, and whether the source workstation shows other suspicious activity. Valid credentials alone do not prove legitimacy. Privileged identity deviations deserve heightened scrutiny because the potential impact of compromise is significant.

Question 254.

Which behavior most strongly suggests defense evasion?

  1. A user opens an approved application
    2. A scheduled backup completes
    3. A normal software update runs
    4. A process disables security tooling, changes exclusions, and deletes related logs

Correct Answer: 4

Explanation:

Disabling security controls, modifying exclusions, and deleting logs are all actions associated with reducing detection visibility. When they occur together, they form a strong defense-evasion pattern. The hunter should inspect the responsible process, user, parent process, commands, and subsequent activity. Centralized telemetry becomes especially important if local evidence has been altered or removed.

Question 255.

A suspicious external IP address appears in events from several endpoints. Which approach best establishes its role?

  1. Review only reputation data
    2. Ignore which processes made the connections
    3. Correlate the IP with hosts, processes, users, timestamps, and related DNS activity
    4. Delete the matching events

Correct Answer: 3

Explanation:

Correlating the IP with local telemetry reveals how the destination was used across the environment. The hunter can identify which processes connected, which users were active, when the connections occurred, and whether there are related domains or other suspicious behaviors. Reputation information can help but does not replace evidence from the organization’s own environment.

Question 256.

Which statement best describes how ATT&CK technique mapping can improve a hunt?

  1. It automatically proves that an attack occurred.
    2. It helps organize observed behavior and suggests related adversary actions to investigate.
    3. It replaces endpoint telemetry.
    4. It should be used only after the hunt is finished.

Correct Answer: 2

Explanation:

Mapping observed activity to ATT&CK tactics and techniques helps hunters organize findings and think about likely next steps. For example, evidence of credential access may lead to searches for lateral movement or persistence. The framework provides structure and consistency, but the actual determination of maliciousness still depends on telemetry, context, and evidence.

Question 257.

A hunter finds an unapproved remote-access tool running on a server. What should be done first?

  1. Investigate installation source, execution history, users, remote destinations, and whether the software is authorized
    2. Assume compromise immediately without analysis
    3. Ignore the tool because remote-access software can be legitimate
    4. Delete all endpoint telemetry

Correct Answer: 1

Explanation:

An unapproved remote-access tool may represent shadow IT, legitimate troubleshooting, or attacker persistence. The hunter should establish how it was installed, who used it, which systems or external destinations it contacted, and whether there is a documented business purpose. Historical execution and cross-host searches can help determine whether the tool is part of a broader suspicious pattern.

Question 258.

Which behavior most strongly suggests privilege escalation?

  1. A standard user opens a browser
    2. A scheduled maintenance task completes
    3. A normal application launches
    4. A low-privilege process unexpectedly produces execution under a system-level context

Correct Answer: 4

Explanation:

An unexpected transition from low privilege to system-level execution can indicate exploitation or abuse of an elevation mechanism. The hunter should inspect the process tree, user identity, command line, elevation path, and actions performed afterward. Legitimate installers can also elevate privileges, so the event should be compared against expected behavior and software context.

Question 259.

Which investigation technique is most useful for understanding how suspicious activity progressed over time?

  1. Reviewing only the detection name
    2. Searching only one hash
    3. Building a chronological timeline of process, file, authentication, and network events
    4. Reviewing only software inventory

Correct Answer: 3

Explanation:

A chronological timeline helps connect isolated events into a meaningful sequence. It can reveal initial execution, persistence, credential access, lateral movement, network communication, and other follow-on actions. Individual alerts may show only one stage of the intrusion. Timelining gives the hunter a broader view and often exposes activity that was not obvious in the original detection.

Question 260.

Which action best completes a threat hunt after malicious behavior has been validated?

  1. Delete the investigation notes
    2. Document findings, establish scope, coordinate response, and convert useful hunting logic into reusable detections or future hunts
    3. Disable related telemetry
    4. Leave findings undocumented

Correct Answer: 2

Explanation:

A completed hunt should support immediate containment and improve future defensive capability. The hunter should document affected systems, users, timelines, behaviors, and important indicators. Useful queries or behavioral patterns can be turned into reusable detections or future hunt analytics. Lessons learned can also reveal telemetry gaps and improve subsequent hunting hypotheses.