View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 301.
A Falcon Hunter notices that a rare process begins executing on several systems shortly after the same user logs in. What should the hunter investigate first?
- The shared user context, process ancestry, command lines, file hash, and activity across the affected hosts
2. Only the executable filename
3. Printer configuration
4. Desktop background settings
Correct Answer: 1
Explanation:
The common user context may provide an important link between the affected systems. The hunter should determine whether the account authenticated to each host, how the rare process was launched, whether the binary or command line is identical, and what activity followed. This can reveal account compromise, software deployment, or another shared cause. Correlating user, host, process, and timing information provides stronger evidence than examining each system independently.
Question 302.
Which behavior most strongly suggests persistence through account creation?
- A user opens an approved application
2. A routine system update runs
3. A standard backup completes
4. An unfamiliar process creates a new privileged local account and the account later logs in
Correct Answer: 4
Explanation:
Creation of a new privileged account followed by successful use of that account can indicate persistence. The hunter should identify which process created the account, the originating user context, creation time, privilege assignment, and subsequent authentication events. Legitimate provisioning can produce similar activity, so the behavior should be compared with approved administrative workflows and change records before concluding that the account is malicious.
Question 303.
Which telemetry is most useful when investigating possible lateral movement involving remote service creation?
- Display settings
2. Printer history
3. Source host, authentication activity, destination host, service creation, and resulting process execution
4. Installed fonts
Correct Answer: 3
Explanation:
Remote service creation can be part of legitimate systems administration or attacker lateral movement. The hunter should correlate the source system, account, authentication events, destination, service definition, and process launched by the service. These details help establish whether the service was created remotely and whether the activity fits expected operational behavior. Process and identity context are essential for distinguishing malicious use from normal administration.
Question 304.
Which approach is most effective when hunting for suspicious use of regsvr32.exe, mshta.exe, or similar trusted utilities?
- Treat every execution as malicious
2. Examine command lines, parent processes, referenced content, users, and related network or file activity
3. Ignore the utilities because they are signed
4. Search only for their executable names
Correct Answer: 2
Explanation:
Trusted utilities can be abused for execution while blending into legitimate system activity. The hunter should focus on how each utility was invoked, what content or files it referenced, which process launched it, and what network or file activity followed. A signed executable is not automatically safe in every context. Behavioral relationships and command-line details provide stronger evidence of suspicious use.
Question 305.
A Falcon Hunter sees a normally common application executed with a command line that has never appeared elsewhere in the environment. What should the hunter do?
- Investigate the unusual command line, parent process, user, host context, and subsequent activity
2. Ignore it because the application is common
3. Delete all events involving the application
4. Assume every instance of the application is malicious
Correct Answer: 1
Explanation:
A common executable can become suspicious when its usage differs significantly from normal patterns. An unusual command line may indicate abuse of legitimate software or execution of attacker-controlled content. The hunter should compare the event against normal instances and review the parent process, user, path, network activity, and follow-on processes. Behavioral anomalies can be more informative than process prevalence alone.
Question 306.
Which behavior most strongly suggests periodic command-and-control traffic?
- A user opens a local document
2. A normal system update occurs
3. A service writes a routine log entry
4. A process repeatedly connects to the same rare external destination at consistent intervals
Correct Answer: 4
Explanation:
Repeated outbound connections at regular intervals can indicate beaconing associated with command-and-control activity. The hunter should examine the process responsible, connection timing, destination rarity, DNS activity, affected hosts, and whether the communication continues without user interaction. Legitimate applications may also communicate periodically, so baseline behavior and software purpose should be considered before reaching a conclusion.
Question 307.
Which event pattern is most relevant when hunting for system-owner or privilege discovery?
- A user opens a normal browser
2. A scheduled update completes
3. A process repeatedly queries current users, groups, privileges, and system identity information
4. A printer job finishes
Correct Answer: 3
Explanation:
Repeated queries about users, groups, privileges, and system identity can indicate discovery activity. Attackers may collect this information to understand available accounts and identify opportunities for privilege escalation or lateral movement. The hunter should examine the responsible process, command line, parent process, user, timing, and any related follow-on activity. Legitimate administrators can perform similar actions, making context important.
Question 308.
Which statement best describes why a hunter might group events by parent process?
- It automatically identifies malware.
2. It can reveal unusual execution relationships and recurring chains across the environment.
3. It eliminates the need to inspect child processes.
4. It is useful only for inventory reporting.
Correct Answer: 2
Explanation:
Grouping events by parent process helps hunters identify common and unusual process relationships. For example, a scripting engine launched by a rarely associated parent may stand out from normal activity. The hunter can then inspect child processes, command lines, users, and network connections to understand the sequence. Aggregation helps prioritize investigation but does not by itself prove maliciousness.
Question 309.
A hunter observes a PDF reader spawning a command interpreter followed by an outbound network connection. What should be investigated next?
- The document origin, process chain, command line, created files, and network destination
2. Only the PDF filename
3. Printer configuration
4. The user’s display resolution
Correct Answer: 1
Explanation:
A document reader launching a command interpreter and generating outbound communication is a suspicious sequence that may indicate exploitation or malicious document execution. The hunter should inspect the document source, process ancestry, command line, file activity, network destination, and any child processes. The combination of unusual execution relationships and network activity provides much more context than any single event.
Question 310.
Which behavior most strongly suggests collection of potentially sensitive information before exfiltration?
- A normal application reads its own configuration
2. A browser loads an approved website
3. A scheduled inventory task runs
4. A process enumerates sensitive directories, copies selected files, and creates a compressed archive
Correct Answer: 4
Explanation:
Enumeration of sensitive locations followed by file collection and compression can indicate preparation for exfiltration. The hunter should determine which files were selected, which process performed the activity, the user context, archive destination, and whether external transfer followed. Legitimate backup or migration processes may behave similarly, so the sequence should be compared with known business operations and historical activity.
Question 311.
Which hunting strategy is most effective against attackers who frequently change binaries but continue using the same discovery and persistence techniques?
- Search only exact hashes
2. Search only filenames
3. Hunt for recurring behavioral patterns and technique sequences
4. Ignore process and persistence telemetry
Correct Answer: 3
Explanation:
Behavioral hunting is more resilient when attackers modify binaries because discovery methods, persistence mechanisms, and execution relationships may remain consistent across tool variants. The hunter can identify these recurring behaviors without depending solely on hashes or filenames. Static indicators remain useful for rapid scoping, but technique-based hunting provides broader coverage when superficial artifacts change.
Question 312.
Which statement best describes the value of comparing process prevalence across hosts?
- Every rare process is malicious.
2. Prevalence helps identify unusual software or behavior that deserves additional context and review.
3. Common processes cannot be malicious.
4. Prevalence replaces command-line analysis.
Correct Answer: 2
Explanation:
Process prevalence helps hunters identify executables that appear on few systems and may deserve closer review. However, rare software can be legitimate, while common tools can be abused. The hunter should combine prevalence with command-line arguments, process ancestry, user context, file path, signer information, and network behavior. Prevalence is a prioritization signal rather than a definitive verdict.
Question 313.
A dormant privileged account suddenly authenticates to several production servers. What should the hunter investigate first?
- Source hosts, authentication methods, destination systems, timing, and activity performed after login
2. Only the account name
3. Printer settings
4. Desktop wallpaper
Correct Answer: 1
Explanation:
A dormant privileged account becoming active across production servers is a significant anomaly. The hunter should determine where the authentications originated, which methods were used, what servers were accessed, and what processes or commands followed. Historical account usage and administrative records can help determine whether the activity was authorized. Because the account is privileged, potential compromise should be investigated promptly.
Question 314.
Which behavior most strongly suggests defense evasion through tampering with monitoring controls?
- A user launches an approved application
2. A routine patch installs
3. A scheduled backup runs
4. A process disables logging or monitoring immediately before executing unfamiliar code
Correct Answer: 4
Explanation:
Disabling monitoring immediately before unfamiliar code executes is highly suspicious because it may indicate an attempt to avoid detection. The hunter should identify which process changed the monitoring state, who initiated it, what code executed afterward, and whether local artifacts were removed. Centralized telemetry may help reconstruct activity that local monitoring failed to record during the affected period.
Question 315.
A suspicious domain appears in DNS requests from several endpoints, but only one host later establishes a network connection. What should the hunter do?
- Ignore all hosts that only performed DNS lookups
2. Assume every DNS lookup proves compromise
3. Compare the requesting processes, users, timestamps, subsequent connections, and host context across all affected systems
4. Delete the DNS events
Correct Answer: 3
Explanation:
DNS lookups alone do not prove that a connection occurred or that a host is compromised. The hunter should compare the processes that made the requests, user context, timing, and whether connections followed. Differences between systems may explain why only one host communicated with the destination. This comparison can help identify whether the DNS activity was malicious, blocked, exploratory, or legitimate.
Question 316.
Which statement best describes the benefit of mapping hunt findings to ATT&CK techniques?
- It reveals the attacker’s exact identity automatically.
2. It provides a common structure for describing behavior and identifying related activities to investigate.
3. It replaces raw telemetry.
4. It guarantees that the mapped behavior is malicious.
Correct Answer: 2
Explanation:
ATT&CK mappings provide a consistent way to describe observed adversary behaviors and connect them to broader tactics. Hunters can use these mappings to identify related techniques that may occur before or after the observed activity. This supports more systematic investigation and communication. The framework does not replace telemetry or prove malicious intent; evidence and environmental context are still required.
Question 317.
A hunter finds a remote-access application that is approved for help-desk systems but is running on a database server. What should the hunter investigate first?
- How it was installed, who executed it, what destinations it contacted, and whether its use on that server was authorized
2. Ignore it because the software is approved somewhere in the organization
3. Immediately classify all use of the tool as malicious
4. Delete the server telemetry
Correct Answer: 1
Explanation:
Software can be legitimate in one part of an environment and suspicious in another. The hunter should determine why the remote-access application appeared on the database server, who installed or executed it, which destinations it contacted, and whether an approved business purpose exists. Asset role and expected software distribution are important contextual factors when identifying misuse.
Question 318.
Which behavior most strongly suggests possible privilege escalation?
- A standard user opens an approved browser
2. A normal application launches
3. A routine system inventory runs
4. A user-level process unexpectedly launches a child process with system-level privileges
Correct Answer: 4
Explanation:
An unexpected transition from user-level execution to system-level privileges can indicate exploitation or abuse of an elevation mechanism. The hunter should examine process ancestry, user context, command line, the method of elevation, and actions performed afterward. Legitimate software installation may also involve elevation, so the event should be compared with expected administrative behavior and application context.
Question 319.
Which investigation technique is most useful when a hunter needs to determine whether several suspicious events are part of one attack chain?
- Review only the highest-severity detection
2. Search only for the malware filename
3. Correlate the events chronologically across process, authentication, file, and network telemetry
4. Review only asset inventory
Correct Answer: 3
Explanation:
Chronological correlation helps determine whether events that appear separately are actually related. The hunter can connect initial execution, persistence, discovery, credential access, network activity, and lateral movement based on timing and shared entities. This helps reconstruct a coherent attack chain and identify gaps between individual detections. Timelines are especially valuable when several low-level events combine into a more significant pattern.
Question 320.
Which action best completes a hunt after the hunter confirms a new malicious technique that was not previously detected automatically?
- Delete the findings
2. Document the behavior, determine scope, coordinate response, and create or improve reusable detections or hunt analytics
3. Disable the associated telemetry
4. Leave the technique undocumented
Correct Answer: 2
Explanation:
A newly confirmed technique should be documented and used to improve both immediate and future defenses. The hunter should identify affected systems and users, preserve the timeline and evidence, and coordinate containment or remediation. Validated behavior can then inform new detection logic or reusable hunting analytics. This feedback loop helps the organization detect similar activity more efficiently in the future.