CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part2 Q21-40

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 21.

A Falcon Hunter is investigating a suspicious process that created several child processes and initiated outbound network connections. What is the best first step?

  1. Review the process tree, command line, user context, and related network activity
    2. Ignore the child processes and focus only on the original executable
    3. Immediately reinstall the endpoint operating system
    4. Disable all endpoint logging

Correct Answer: 1

Explanation:

A process tree gives the hunter essential context about how suspicious activity developed. Reviewing parent and child processes, command-line arguments, user identity, and outbound connections can reveal whether the activity represents legitimate administration, malicious scripting, persistence, or command-and-control behavior. Investigating only the original executable can miss important follow-on actions. A hunter should first reconstruct the behavior before deciding whether containment or remediation is necessary.

Question 22.

A hunter wants to identify every host where a specific suspicious SHA-256 hash executed. Which action is most appropriate?

  1. Search only the original detection
    2. Review only user-account events
    3. Examine printer configuration logs
    4. Search enterprise telemetry for the hash and summarize affected hosts

Correct Answer: 4

Explanation:

Searching enterprise telemetry for the suspicious hash helps determine whether the file was isolated to one endpoint or appeared across multiple systems. The hunter can then pivot into execution time, parent process, user, host, and associated network activity. This is important for determining incident scope. File hashes should not be treated as the only source of truth, however, because attackers can alter binaries and change hashes while preserving the same behavior.

Question 23.

Which type of activity is most useful when hunting for lateral movement?

  1. Screen resolution changes
    2. Local file compression activity only
    3. Remote logons, administrative share access, and remote process execution
    4. Printer queue activity

Correct Answer: 3

Explanation:

Lateral movement often involves remote authentication, administrative shares, remote service creation, remote desktop sessions, or execution tools that operate across systems. These behaviors can be correlated with user identity, source host, destination host, and process telemetry to determine whether the activity is legitimate administration or attacker movement. Peripheral activity such as printer events or screen settings provides little value when investigating lateral movement.

Question 24.

A detection shows a command interpreter launching from an unusual application process. Which investigation approach is best?

  1. Assume the behavior is benign if the interpreter is signed
    2. Review the parent process, command-line arguments, children, and subsequent activity
    3. Delete all process telemetry
    4. Ignore the detection if no malware file is present

Correct Answer: 2

Explanation:

Attackers frequently abuse trusted command interpreters, so the fact that an executable is legitimate or digitally signed does not make its use benign. The hunter should examine the parent application, command-line parameters, child processes, network activity, and related file operations. This context can reveal exploitation, script execution, or living-off-the-land techniques that would be missed if the investigation focused only on known malware files.

Question 25.

A Falcon Hunter wants to determine whether a suspicious user account was active on multiple systems during the same time period. What should the hunter do?

  1. Search authentication and endpoint telemetry for the account across hosts and time
    2. Review only one host’s file system
    3. Search only for the user’s email address
    4. Disable identity logging

Correct Answer: 1

Explanation:

Searching authentication and endpoint telemetry across systems can reveal where and when the user account was active. The hunter can identify unusual source hosts, destination systems, concurrent activity, remote logons, privilege use, and related processes. This helps determine whether the account may have been compromised or used for lateral movement. A single-host review may miss broader identity activity occurring elsewhere in the environment.

Question 26.

Which behavior most strongly suggests a possible persistence mechanism?

  1. A browser launches normally
    2. A scheduled inventory scan runs
    3. A user opens a business application
    4. A suspicious process creates a new scheduled task that launches an unknown executable

Correct Answer: 4

Explanation:

Creating a scheduled task that repeatedly launches an unknown executable can provide persistence across reboots or user sessions. The hunter should inspect the task definition, executing account, executable path, creation time, parent process, and subsequent executions. Scheduled tasks also have many legitimate uses, so surrounding context is important. Persistence hunting should focus on unexpected creation or modification patterns rather than treating every scheduled task as malicious.

Question 27.

A hunter sees a process accessing credential-related memory and then making remote connections. Which ATT&CK-related behavior should receive additional investigation?

  1. Impact only
    2. Initial access only
    3. Credential access followed by possible lateral movement
    4. Resource development only

Correct Answer: 3

Explanation:

Access to credential material followed by remote connections may indicate a sequence in which an attacker obtains credentials and then uses them to move to additional systems. The hunter should examine the responsible process, affected accounts, remote destinations, authentication events, and resulting processes. Thinking in terms of adversary tactics and techniques helps identify likely next steps and guides additional searches beyond the initial detection.

Question 28.

Which approach is most appropriate when a threat hunter finds thousands of matching events during a search?

  1. Review every event individually before doing anything else
    2. Aggregate or group results by meaningful fields such as host, user, process, or destination
    3. Delete the search results
    4. Stop the hunt because there are too many events

Correct Answer: 2

Explanation:

Aggregation helps reveal patterns in large data sets. Grouping results by hostname, process, user, command line, or destination can identify outliers, frequently affected systems, or common execution paths. Hunters can then drill into the most relevant individual events. Large result sets are common in enterprise environments, so effective hunting often requires summarization before detailed event-level analysis.

Question 29.

A hunter wants to know whether an unusual executable name is actually a renamed known tool. Which evidence is most useful?

  1. Compare the file hash, path, metadata, and process behavior
    2. Trust the filename completely
    3. Ignore the file hash
    4. Review only the user’s job title

Correct Answer: 1

Explanation:

Attackers can rename legitimate or malicious tools to evade simple filename-based detections. Comparing the hash, execution path, metadata, parent process, command line, and behavior can reveal that the file’s identity does not match its visible name. Hashes alone are not always sufficient because modified tools can produce different hashes, so behavioral evidence should also be considered.

Question 30.

Which activity best indicates potential command-and-control communication?

  1. A user launches a calculator
    2. A scheduled local backup completes
    3. A printer driver loads
    4. A suspicious process repeatedly connects to a rare external domain at regular intervals

Correct Answer: 4

Explanation:

Repeated outbound communication at predictable intervals can be consistent with beaconing behavior used by command-and-control frameworks. The hunter should inspect the initiating process, connection frequency, destination domain, host distribution, DNS activity, and any data transferred. Legitimate software can also produce periodic connections, so the behavior should be validated using local context rather than treated as malicious solely because of timing.

Question 31.

Which search pivot is most useful after identifying a suspicious domain in endpoint telemetry?

  1. Screen brightness
    2. Printer model
    3. Hosts, processes, users, and timestamps associated with connections to that domain
    4. Installed fonts

Correct Answer: 3

Explanation:

Pivoting from a suspicious domain to the systems and processes that contacted it helps establish the scope and context of the activity. The hunter can determine which hosts were involved, which users were active, what process initiated the connection, and whether activity occurred in a coordinated time window. This provides much stronger investigative value than treating the domain as an isolated indicator.

Question 32.

What is the main purpose of establishing a baseline during threat hunting?

  1. To automatically classify all uncommon activity as malicious
    2. To understand normal behavior so meaningful deviations can be identified
    3. To eliminate the need for event searches
    4. To prevent all false positives

Correct Answer: 2

Explanation:

A baseline helps hunters understand what is typical for a user, host, process, or environment. Deviations from normal behavior can then become useful hunting leads. Uncommon activity is not automatically malicious, so anomalies must still be investigated in context. Baselines are particularly helpful when hunting for account compromise, unusual process execution, abnormal network communication, or rare administrative behavior.

Question 33.

A hunter identifies a process launching from a temporary directory with a rare filename and an unusual parent. What should the hunter do next?

  1. Examine the process tree, hash, command line, network activity, and related hosts
    2. Ignore it because temporary directories are always safe
    3. Delete all endpoint evidence
    4. Search only the hostname

Correct Answer: 1

Explanation:

Execution from a temporary directory, combined with a rare filename and unusual parent process, provides several suspicious contextual signals. The hunter should inspect the full process tree, file identity, command line, network connections, and whether the same behavior appears elsewhere. No single characteristic proves malicious activity, but multiple unusual attributes increase the value of the hunting lead.

Question 34.

Which behavior would be most relevant when investigating possible data exfiltration?

  1. A normal user login
    2. A routine local process startup
    3. A scheduled inventory task
    4. Large outbound transfers from a process that normally has little external network activity

Correct Answer: 4

Explanation:

An unusual increase in outbound data from a process that normally communicates little or not at all externally can indicate possible exfiltration. The hunter should examine the process, destination, data volume, user context, timing, and any file-access activity preceding the transfer. Legitimate software updates or backups can also generate large transfers, so validation against baseline behavior and business purpose is necessary.

Question 35.

A Falcon Hunter suspects an attacker used a legitimate remote administration utility. What is the best way to distinguish malicious from legitimate use?

  1. Block every instance of the utility automatically
    2. Trust it because it is digitally signed
    3. Evaluate user, source host, destination, command line, timing, and related behavior
    4. Review only the executable filename

Correct Answer: 3

Explanation:

Remote administration utilities may be used by both administrators and attackers. Context determines whether the activity is suspicious. The hunter should examine who executed the tool, from which endpoint, which destination was accessed, what commands were used, and whether the timing matches expected administrative activity. Signed executables can still be abused, so digital signatures alone do not establish legitimate use.

Question 36.

Which statement best describes hypothesis-driven hunting?

  1. It relies only on existing detections
    2. It begins with a testable assumption about adversary behavior and uses telemetry to evaluate it
    3. It avoids using threat intelligence
    4. It requires every hunt to find malicious activity

Correct Answer: 2

Explanation:

Hypothesis-driven hunting starts with a specific, testable idea about attacker behavior or environmental risk. The hunter identifies relevant data sources, constructs searches, analyzes results, and determines whether the evidence supports or rejects the hypothesis. A successful hunt does not have to discover an intrusion; it can also validate controls, reveal telemetry gaps, or improve future detection logic.

Question 37.

Which action best helps determine the scope of a suspicious PowerShell command found on one endpoint?

  1. Search for the command pattern, related processes, users, and network indicators across the environment
    2. Search only the original endpoint
    3. Ignore command-line telemetry
    4. Disable PowerShell logging

Correct Answer: 1

Explanation:

Enterprise-wide searching can show whether the suspicious PowerShell behavior occurred elsewhere and whether multiple systems share common users, parent processes, destinations, or payloads. This helps distinguish an isolated event from coordinated activity. Command-line telemetry is especially valuable because attackers may use legitimate PowerShell binaries while changing scripts or arguments between hosts.

Question 38.

Which activity is most suspicious during a hunt for defense evasion?

  1. An approved browser update
    2. A scheduled compliance scan
    3. A user opens a routine document
    4. A process attempts to disable security services and then deletes its own execution artifacts

Correct Answer: 4

Explanation:

Disabling security services and deleting execution artifacts are behaviors commonly associated with attempts to avoid detection or forensic analysis. The hunter should inspect the responsible process, user context, command line, parent process, affected security controls, and subsequent activity. The combination of multiple defense-evasion behaviors is more significant than either event in isolation and should be treated as a strong investigative lead.

Question 39.

Which hunting technique is most useful for finding adversaries who frequently change file hashes but continue using similar execution patterns?

  1. Searching only for exact hashes
    2. Searching only for filenames
    3. Behavioral hunting based on process relationships, command lines, and activity sequences
    4. Ignoring endpoint process telemetry

Correct Answer: 3

Explanation:

Behavioral hunting focuses on how adversaries operate instead of relying only on static indicators such as file hashes. Attackers can easily modify files to produce new hashes, but their execution patterns, parent-child relationships, command syntax, network behavior, or persistence methods may remain similar. Behavioral analytics therefore provide greater resilience against minor changes in attacker tooling.

Question 40.

Which approach best represents the final stage of a productive threat hunt after suspicious activity has been validated?

  1. Delete the hunting query
    2. Document findings, determine scope, improve detections, and feed lessons back into future hunts
    3. Keep the findings undocumented
    4. Stop collecting telemetry related to the behavior

Correct Answer: 2

Explanation:

A productive hunt should improve the organization’s future defensive capability. After validating suspicious activity, the hunter should document the findings, determine affected systems and users, support response where necessary, and identify opportunities to improve detections or telemetry. Useful hunting logic may become a reusable analytic. Lessons learned can also guide future hypotheses and help defenders recognize similar adversary behavior more quickly.