View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 341.
A Falcon Hunter identifies a suspicious executable that appears on several hosts but is launched by different parent processes. What should the hunter investigate first?
- Compare the hash, paths, command lines, users, parent processes, and follow-on activity across all affected hosts
2. Review only the first host where the file appeared
3. Ignore the parent-process differences
4. Delete all related telemetry
Correct Answer: 1
Explanation:
Comparing the same executable across multiple hosts helps determine whether the activity represents a common deployment, malware distribution, or separate unrelated events. Differences in parent processes can reveal different execution paths or delivery methods. The hunter should compare file hashes, paths, command lines, users, timestamps, network connections, and child processes. Cross-host analysis provides a stronger picture of scope and behavior than examining a single endpoint in isolation.
Question 342.
Which behavior most strongly suggests persistence through modification of an existing service?
- A user opens a normal browser
2. A scheduled inventory task executes
3. A routine software patch installs
4. A service’s executable path is changed to launch an unfamiliar binary at system startup
Correct Answer: 4
Explanation:
Changing an existing service so that it launches an unfamiliar binary can provide persistence and may help malicious activity blend with trusted system components. The hunter should identify the process and account responsible for the modification, review the new binary, and examine subsequent service starts. Legitimate software upgrades can also modify services, so timing, signer information, and deployment records should be considered during validation.
Question 343.
Which telemetry is most useful when investigating suspicious remote execution associated with a privileged account?
- Printer configuration
2. Desktop wallpaper
3. Source host, destination host, authentication events, privileged account activity, and resulting processes
4. Installed fonts
Correct Answer: 3
Explanation:
Remote execution involving a privileged identity should be analyzed by correlating authentication and endpoint telemetry. The hunter should determine where the connection originated, which destination was accessed, how the account authenticated, and what processes or commands executed afterward. Privileged accounts can perform legitimate remote administration, so historical usage, source systems, timing, and business context are important for distinguishing expected behavior from compromise.
Question 344.
Which approach is most effective when a hunter sees suspicious execution of a legitimate signed binary?
- Assume the binary is safe because it is signed
2. Examine the command line, process ancestry, user context, path, and resulting behavior
3. Ignore all signed software during hunts
4. Search only the executable name
Correct Answer: 2
Explanation:
A digital signature can establish software provenance but does not guarantee that every use of the program is legitimate. Attackers may abuse signed utilities for execution, discovery, or defense evasion. The hunter should examine how the binary was launched, the command-line arguments, its parent process, user, location, and follow-on activity. Behavioral context is therefore essential even when the executable itself is trusted.
Question 345.
A Falcon Hunter sees an executable with high prevalence but only one host uses an unusual command-line argument. What should the hunter do?
- Investigate the unusual command line, parent process, user context, and subsequent activity on that host
2. Ignore the event because the executable is common
3. Delete all events involving the executable
4. Assume all executions are malicious
Correct Answer: 1
Explanation:
High prevalence does not mean every execution is benign. A common executable may be abused with unusual arguments or launched in an unexpected context. The hunter should compare the anomalous command line with normal instances, then review the parent process, user, path, file activity, and network behavior. The deviation from baseline may be more significant than the prevalence of the executable itself.
Question 346.
Which pattern most strongly suggests possible command-and-control traffic?
- A user opens a local application
2. A normal backup completes
3. A routine update checks for patches
4. A process repeatedly communicates with a rare destination at regular intervals while the user is inactive
Correct Answer: 4
Explanation:
Regular outbound communication to an uncommon destination, especially when no user is active, can indicate automated command-and-control behavior. The hunter should review the process responsible, interval pattern, destination, DNS activity, and whether similar behavior exists on other endpoints. Legitimate services may also communicate in the background, so software purpose and historical baseline should be considered before determining maliciousness.
Question 347.
Which event pattern is most relevant when hunting for network discovery activity?
- A user opens a document
2. A browser connects to an approved website
3. A process repeatedly enumerates network interfaces, routes, neighboring systems, or reachable resources
4. A printer job completes
Correct Answer: 3
Explanation:
Repeated enumeration of network configuration and reachable systems can indicate network discovery. Attackers often perform discovery before choosing lateral-movement targets. The hunter should examine the process, command line, user, parent process, timing, and whether remote authentication or scanning activity follows. Administrators may perform similar actions, so the host role and user context should also be evaluated.
Question 348.
Which statement best describes the value of grouping events by command-line arguments?
- It proves every rare argument is malicious.
2. It can reveal uncommon execution patterns and repeated behaviors that differ from normal usage.
3. It eliminates the need to review parent processes.
4. It is useful only for software inventory.
Correct Answer: 2
Explanation:
Grouping by command-line arguments can expose rare or recurring usage patterns that would be difficult to notice in raw event data. A commonly used process may have one unusual argument set associated with suspicious hosts. The hunter can then drill into parent processes, users, paths, and network activity. Command-line grouping helps prioritize investigation but does not by itself establish malicious intent.
Question 349.
A hunter observes a browser spawning a utility that retrieves a remote file and then launches it. What should be investigated next?
- The browser activity, process chain, retrieval command, downloaded file, destination, and subsequent execution
2. Only the browser version
3. Printer history
4. Screen brightness
Correct Answer: 1
Explanation:
A browser spawning a utility that retrieves and executes a remote file is a suspicious chain that may indicate exploitation or user-assisted malware delivery. The hunter should reconstruct the process sequence, identify the retrieval source, review the downloaded file’s hash and path, and inspect what happened after execution. Correlating these events can help determine whether the behavior is isolated or part of a larger campaign.
Question 350.
Which behavior most strongly suggests data staging before exfiltration?
- A user opens a standard application
2. A normal service writes a log file
3. A routine update completes
4. A process enumerates sensitive files, copies selected data to a temporary folder, and creates an archive
Correct Answer: 4
Explanation:
Enumeration, collection, and compression of sensitive data can indicate staging before exfiltration. The hunter should determine which files were gathered, the process and account involved, the archive destination, and whether unusual outbound traffic followed. Legitimate backup or migration workflows may create similar patterns, so the behavior should be compared with known business operations and historical activity.
Question 351.
Which hunting strategy is most effective when adversaries regularly change hashes and domains but reuse the same sequence of discovery, persistence, and execution behaviors?
- Search only known hashes
2. Search only known domains
3. Hunt for the recurring behavior chain and associated process relationships
4. Ignore process telemetry
Correct Answer: 3
Explanation:
Behavior chains are more durable than individual indicators because attackers can change hashes and infrastructure quickly. Repeated discovery, persistence, and execution patterns may remain recognizable across variants. Hunters should focus on those techniques, process relationships, and event sequences while still using known indicators for immediate scoping. This approach improves coverage against evolving attacker tooling.
Question 352.
Which statement best describes the value of baselining privileged-account activity?
- It proves all common privileged actions are legitimate.
2. It helps identify unusual source hosts, destinations, times, and administrative behaviors.
3. It eliminates the need for event review.
4. It automatically blocks anomalous activity.
Correct Answer: 2
Explanation:
Privileged accounts often have recognizable patterns of systems, tools, and working hours. Establishing a baseline helps identify deviations such as access from unusual workstations, unexpected servers, or unfamiliar commands. An anomaly does not automatically indicate compromise, but it provides a useful lead. Because privileged accounts can have broad impact, unusual behavior should be investigated carefully.
Question 353.
A privileged account begins logging in from a user workstation instead of its normal administrative jump host. What should the hunter investigate first?
- Source workstation, authentication method, destination systems, timing, and resulting privileged actions
2. Only the account name
3. Printer queue activity
4. Desktop theme
Correct Answer: 1
Explanation:
A privileged account authenticating from an unexpected workstation may indicate credential theft, policy bypass, or a legitimate exception. The hunter should determine how the account authenticated, which systems it accessed, and what privileged actions followed. The source workstation should also be checked for suspicious process or credential activity. Comparing the event with historical account behavior can help determine whether the deviation is authorized.
Question 354.
Which behavior most strongly suggests defense evasion through security configuration changes?
- A user opens an approved application
2. A normal software update runs
3. A scheduled backup completes
4. A process modifies security exclusions and disables monitoring before launching an unfamiliar executable
Correct Answer: 4
Explanation:
Changing exclusions and disabling monitoring immediately before launching unfamiliar code strongly suggests an attempt to evade security controls. The hunter should inspect the process responsible, account, command line, parent process, and any subsequent activity. The timing between the configuration changes and executable launch is especially important. Centralized telemetry may preserve evidence even if local monitoring was impaired.
Question 355.
A suspicious domain appears in DNS queries across multiple hosts, but only some hosts make outbound connections. What should the hunter do?
- Treat every DNS query as confirmed compromise
2. Ignore hosts that did not connect
3. Compare the requesting processes, users, timestamps, connection attempts, and host context across all systems
4. Delete all DNS events
Correct Answer: 3
Explanation:
A DNS request does not necessarily mean a successful connection or malicious activity. The hunter should compare which process made the request, whether a connection followed, which user was active, and how the hosts differ. This can reveal blocked communications, legitimate lookups, or varying stages of suspicious activity. Cross-host comparison helps avoid overinterpreting DNS telemetry in isolation.
Question 356.
Which statement best describes how ATT&CK can help identify investigative gaps?
- It automatically detects missing telemetry.
2. Mapping observed techniques can highlight related tactics or behaviors for which the hunter has not yet searched.
3. It replaces the need for endpoint data.
4. It proves all mapped activity is malicious.
Correct Answer: 2
Explanation:
Mapping observed behavior to ATT&CK can reveal logical gaps in an investigation. For example, if the hunter finds credential access and lateral movement but has not examined persistence, the framework may suggest additional areas to search. ATT&CK supports systematic thinking and consistent terminology, but the hunter still needs local telemetry to determine whether related techniques actually occurred.
Question 357.
A hunter finds an approved administrative tool running on a system where it is not normally installed. What should be investigated first?
- Installation source, execution path, user, command line, destinations, and whether the use is authorized on that system
2. Ignore it because the tool is approved somewhere in the organization
3. Assume all use of the tool is malicious
4. Delete the host telemetry
Correct Answer: 1
Explanation:
Software approval does not mean the tool is expected on every asset. The hunter should determine how it appeared on the system, who executed it, what commands were used, and which destinations it contacted. Asset role and software distribution policy provide important context. Unexpected deployment of legitimate administration software can indicate misuse or unauthorized remote access.
Question 358.
Which behavior most strongly suggests privilege escalation?
- A user launches a normal browser
2. A scheduled inventory task runs
3. An approved application opens
4. A low-privilege process unexpectedly causes execution under a highly privileged system account
Correct Answer: 4
Explanation:
An unexpected transition from a low-privilege process to a highly privileged system context can indicate privilege escalation. The hunter should examine process ancestry, user identity, command-line arguments, the elevation mechanism, and actions performed afterward. Legitimate software installations may also elevate privileges, so signer information, deployment context, and historical behavior should be considered.
Question 359.
Which investigation technique is most useful for determining whether discovery activity led to lateral movement?
- Review only the discovery command
2. Search only the source hostname
3. Build a timeline that correlates discovery, authentication, remote access, and resulting process activity
4. Review only asset inventory
Correct Answer: 3
Explanation:
A timeline can show whether discovery was followed by authentication to identified systems and then by remote process execution. This helps establish whether separate events form one attack sequence. Correlating users, hosts, processes, and timestamps provides stronger evidence than reviewing the discovery event by itself. Timelining is particularly useful for understanding progression across multiple stages of an intrusion.
Question 360.
Which action best completes a hunt after the hunter identifies and validates a new attack pattern?
- Delete the investigation notes
2. Document the pattern, establish scope, coordinate response, and improve reusable detection or hunting analytics
3. Disable the associated telemetry
4. Leave the findings undocumented
Correct Answer: 2
Explanation:
A validated attack pattern should improve both immediate response and future detection capability. The hunter should document affected hosts, users, timelines, indicators, and behaviors, then coordinate containment or remediation where appropriate. The confirmed pattern can be translated into new or improved detection logic and reusable hunting analytics, allowing similar activity to be identified more efficiently in the future.