CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part17 Q321-340

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 321.

A Falcon Hunter identifies a process that runs from an unusual path and immediately launches several child processes. What should the hunter investigate first?

  1. The full process tree, command lines, file hash, user context, and related network or file activity
    2. Only the executable filename
    3. Printer configuration
    4. Desktop wallpaper settings

Correct Answer: 1

Explanation:

An unusual execution path combined with multiple child processes can indicate suspicious activity, but the surrounding context is essential. The hunter should review process ancestry, command-line arguments, file hashes, users, created files, and network connections. This helps determine whether the process is part of legitimate software, an installer, or malicious execution. Focusing only on the filename provides too little information because attackers can easily rename tools.

Question 322.

Which behavior most strongly suggests persistence through a startup folder or similar automatic launch mechanism?

  1. A user opens an approved browser
    2. A normal software update completes
    3. A routine inventory scan runs
    4. An unfamiliar executable is placed in a location that causes it to launch automatically when the user logs in

Correct Answer: 4

Explanation:

Placing an executable in an automatic startup location can provide persistence across user sessions. The hunter should identify which process created the file, which user was involved, when it was added, and whether the executable appears elsewhere. Legitimate applications can also configure startup behavior, so the file’s signer, path, rarity, and related activity should be reviewed before determining whether the behavior is malicious.

Question 323.

Which telemetry is most useful when investigating suspicious remote logons followed by process execution?

  1. Local display settings
    2. Printer queues
    3. Source host, destination host, account, authentication events, and resulting process activity
    4. Installed fonts

Correct Answer: 3

Explanation:

Remote logons become more meaningful when correlated with what happened afterward. The hunter should identify the source system, destination, user account, authentication method, and processes launched on the destination. This helps distinguish routine administration from lateral movement. Authentication alone may show that access occurred, but it does not reveal whether suspicious commands or tools were executed after the session began.

Question 324.

Which approach is most effective when investigating suspicious use of PowerShell or another legitimate scripting interpreter?

  1. Treat every script execution as malicious
    2. Analyze command-line arguments, parent process, user context, created files, and network activity
    3. Ignore the interpreter because it is built into the operating system
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Scripting interpreters are widely used for legitimate administration and automation, so their presence alone is not suspicious. The hunter should focus on how the interpreter was launched, which arguments were passed, what files were created, what processes followed, and whether network communication occurred. Behavioral context helps distinguish legitimate use from malicious scripting far more effectively than simply searching for the interpreter name.

Question 325.

A Falcon Hunter discovers a common process running under an account that normally never uses it. What should the hunter do?

  1. Investigate the user context, command line, parent process, execution path, and related activity
    2. Ignore it because the process is common
    3. Delete all events involving the process
    4. Assume every instance is malicious

Correct Answer: 1

Explanation:

A common process can still be suspicious when used by an unusual account or in an unexpected context. The hunter should compare the event against the account’s historical behavior and examine the command line, parent process, execution path, and any related network or file activity. User-context anomalies can provide valuable hunting leads even when the executable itself is common across the environment.

Question 326.

Which pattern most strongly suggests possible automated beaconing?

  1. A user opens a spreadsheet
    2. A normal application reads a local file
    3. A scheduled maintenance job runs
    4. A process repeatedly connects to the same uncommon external address at nearly regular intervals

Correct Answer: 4

Explanation:

Repeated outbound communication at regular or near-regular intervals can indicate beaconing to command-and-control infrastructure. The hunter should examine the initiating process, destination, timing, DNS activity, and whether similar behavior appears elsewhere. Legitimate software may also communicate periodically, so the process purpose and historical baseline should be considered before concluding the activity is malicious.

Question 327.

Which event pattern is most relevant when hunting for account or group discovery?

  1. A browser opens an approved site
    2. A normal application update runs
    3. A process repeatedly queries users, groups, privileges, and account memberships
    4. A user prints a document

Correct Answer: 3

Explanation:

Repeated queries about users, groups, memberships, and privileges may indicate account discovery. Attackers often gather this information to identify valuable identities or understand privilege relationships before attempting escalation or lateral movement. The hunter should review the responsible process, command line, parent process, user, and any follow-on actions. Legitimate administrators may perform similar activity, so role and timing matter.

Question 328.

Which statement best describes the value of grouping hunt results by user and host together?

  1. It automatically proves account compromise.
    2. It can reveal unusual user-to-host relationships and concentrated suspicious activity.
    3. It replaces process analysis.
    4. It is useful only for asset inventory.

Correct Answer: 2

Explanation:

Grouping by user and host can reveal relationships that stand out from normal behavior, such as a user suddenly appearing on systems they do not normally access. It can also highlight hosts associated with multiple suspicious identities. Aggregation helps prioritize investigation, but hunters should still drill into authentication, process, command-line, and network events before reaching conclusions.

Question 329.

A hunter observes a browser launching a command interpreter that creates an executable in a temporary directory. What should be investigated next?

  1. The browser activity, process chain, command line, created file, source, and subsequent execution
    2. Only the browser version
    3. Printer settings
    4. Screen resolution

Correct Answer: 1

Explanation:

A browser spawning a command interpreter and creating an executable can indicate exploitation, malicious downloads, or social-engineering-driven execution. The hunter should reconstruct the process chain, inspect command-line arguments, identify the created file and source, and review any follow-on execution or network activity. The full sequence provides stronger evidence than any individual process alone.

Question 330.

Which behavior most strongly suggests data collection and staging?

  1. A user opens a routine application
    2. A normal update installs
    3. A service writes a small log entry
    4. A process searches for documents, copies selected files to one directory, and compresses them

Correct Answer: 4

Explanation:

Searching for documents, collecting them into one staging location, and compressing them can indicate preparation for exfiltration. The hunter should determine which files were selected, who initiated the activity, what process performed it, and whether an external transfer followed. Legitimate backup or migration workflows can look similar, so business context and historical patterns should be considered.

Question 331.

Which hunting approach is most effective when attackers continuously modify binaries but repeat the same execution and persistence patterns?

  1. Search only exact hashes
    2. Search only filenames
    3. Hunt for recurring behavioral patterns and process relationships
    4. Ignore persistence telemetry

Correct Answer: 3

Explanation:

Static indicators such as hashes and filenames can change easily, while execution and persistence behaviors may remain consistent across variants. Hunting for recurring process relationships, command structures, scheduled tasks, services, or startup changes provides broader coverage. Static indicators still help with immediate scoping, but behavioral hunting is more resilient against changing attacker tools.

Question 332.

Which statement best describes the value of baselining authentication behavior?

  1. It proves all common authentication is legitimate.
    2. It helps identify unusual source systems, destinations, times, or methods associated with an account.
    3. It removes the need for investigation.
    4. It automatically blocks every unusual login.

Correct Answer: 2

Explanation:

Authentication baselines help hunters understand where, when, and how accounts normally access systems. Deviations such as unusual source hosts, new destinations, or unexpected login times can become useful hunting leads. These anomalies are not automatically malicious, so they should be validated using account role, process activity, and historical behavior. Baselines help prioritize investigation rather than replace it.

Question 333.

A user account that normally works only on workstations begins authenticating to several servers. What should the hunter investigate first?

  1. Source hosts, authentication methods, destination servers, timing, and resulting activity
    2. Only the user’s display name
    3. Printer configuration
    4. Desktop theme

Correct Answer: 1

Explanation:

Unexpected server access by a workstation-focused account may indicate credential compromise, role change, or legitimate administrative activity. The hunter should determine where the authentications originated, which servers were accessed, what methods were used, and what processes or commands followed. Historical account behavior and business role are important for deciding whether the access is expected.

Question 334.

Which behavior most strongly suggests defense evasion through logging impairment?

  1. A user opens an approved application
    2. A scheduled backup completes
    3. A routine update runs
    4. A process disables logging and then performs unfamiliar system changes

Correct Answer: 4

Explanation:

Disabling logging immediately before unfamiliar system changes can indicate an attempt to reduce visibility. The hunter should identify which process changed logging settings, the user involved, what modifications followed, and whether other evidence exists in centralized telemetry. The timing between monitoring impairment and suspicious actions is particularly important when evaluating possible defense evasion.

Question 335.

A suspicious domain is queried by several hosts, but the responsible processes differ. What should the hunter do?

  1. Assume every process is part of the same attack
    2. Ignore the domain because different processes contacted it
    3. Compare process context, users, timestamps, DNS activity, and subsequent network behavior across the hosts
    4. Delete the DNS events

Correct Answer: 3

Explanation:

Different processes contacting the same domain can indicate unrelated legitimate activity, shared infrastructure, or coordinated malicious behavior. The hunter should compare the processes, users, timing, and subsequent connections to understand whether the events are connected. Domain reputation can add context, but local process and host evidence are essential for determining significance.

Question 336.

Which statement best describes how ATT&CK can support hypothesis development?

  1. It identifies the attacker’s identity automatically.
    2. It helps hunters translate known tactics and techniques into testable questions against local telemetry.
    3. It replaces threat hunting queries.
    4. It guarantees any technique match is malicious.

Correct Answer: 2

Explanation:

ATT&CK provides documented adversary behaviors that can be translated into hunting hypotheses. A hunter might use a technique description to ask whether a particular type of persistence, discovery, or lateral-movement behavior exists in the environment. The framework provides structure, but the hypothesis still has to be tested against real telemetry and interpreted in the organization’s operational context.

Question 337.

A hunter finds an approved remote-support tool running from an unexpected directory and under an unusual account. What should be investigated first?

  1. The executable path, user, parent process, command line, network destinations, and whether the behavior matches approved use
    2. Ignore it because the tool is approved
    3. Assume all instances of the tool are malicious
    4. Delete the endpoint telemetry

Correct Answer: 1

Explanation:

Approved software can still be abused or copied into unexpected locations. The hunter should compare the executable path and hash with legitimate versions, identify the account using it, review process ancestry, and inspect remote destinations. Authorization applies to expected deployment and usage, not every possible execution context. Deviations from approved patterns should therefore be validated carefully.

Question 338.

Which behavior most strongly suggests possible privilege escalation?

  1. A browser launches normally
    2. A standard user opens an approved application
    3. A scheduled inventory process runs
    4. A low-privilege process unexpectedly results in execution with system-level rights

Correct Answer: 4

Explanation:

An unexpected transition from low privilege to system-level execution may indicate exploitation or abuse of an elevation mechanism. The hunter should review process ancestry, user identity, command-line activity, the privilege transition, and actions performed afterward. Legitimate installers and administrative workflows can also elevate privileges, so context and expected software behavior must be considered.

Question 339.

Which investigation technique is most useful when determining whether authentication, process, and network events are part of the same incident?

  1. Review only the most severe alert
    2. Search only one process name
    3. Correlate the events by entity and timestamp in a chronological timeline
    4. Review only the host inventory

Correct Answer: 3

Explanation:

Correlating events by time and shared entities such as users, hosts, and processes helps determine whether seemingly separate activities are connected. A timeline can show an unusual logon followed by process execution and then outbound communication. This broader view can reveal an attack chain that individual events might not expose on their own.

Question 340.

Which action best completes a hunt after the hunter confirms a malicious pattern across multiple endpoints?

  1. Delete the hunt data
    2. Document findings, determine scope, coordinate response, and improve reusable detection or hunting analytics
    3. Disable related telemetry
    4. Leave the findings undocumented

Correct Answer: 2

Explanation:

Once malicious behavior is confirmed across multiple systems, the hunt should support both immediate response and long-term improvement. The hunter should document affected hosts, users, timelines, indicators, and behaviors, then coordinate containment and remediation. Validated patterns can also be turned into reusable detections or hunting analytics so similar activity can be identified more efficiently in the future.