CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part20 Q381-400

View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps

 

Question 381.

A Falcon Hunter notices a rare process running from a temporary directory shortly after a user opens an email attachment. What should the hunter investigate first?

  1. The attachment source, process ancestry, command line, file hash, user context, and subsequent activity
    2. Only the process filename
    3. Printer configuration
    4. Desktop theme settings

Correct Answer: 1

Explanation:

A rare process launching from a temporary directory after an attachment is opened can indicate malicious document execution or user-delivered malware. The hunter should reconstruct the complete sequence, including the attachment origin, parent process, command line, file hash, user context, and any subsequent process or network activity. The filename or path alone is not sufficient evidence. Correlating delivery, execution, and follow-on behavior provides a much stronger basis for determining whether the activity is malicious.

Question 382.

Which behavior most strongly suggests persistence through an autorun mechanism?

  1. A user opens an approved application
    2. A routine update runs
    3. A scheduled inventory task completes
    4. An unfamiliar executable is configured to launch automatically whenever the user signs in

Correct Answer: 4

Explanation:

An unfamiliar executable configured to launch automatically at logon may provide persistence. The hunter should identify which process created the autorun entry, which user was affected, where the executable resides, and whether the same mechanism appears elsewhere. Legitimate applications can also configure startup behavior, so signer information, timing, path, rarity, and related execution should be reviewed before classifying the event as malicious.

Question 383.

Which telemetry is most useful when investigating suspected lateral movement that uses a privileged account?

  1. Screen brightness
    2. Printer history
    3. Source and destination hosts, authentication events, account activity, and resulting process execution
    4. Installed fonts

Correct Answer: 3

Explanation:

Lateral movement involving privileged credentials should be investigated by correlating authentication and endpoint telemetry. The hunter should identify where the access originated, which destination systems were reached, how the privileged account authenticated, and what processes or commands executed afterward. Comparing these events with the account’s normal administrative pattern helps distinguish legitimate activity from compromise. Identity and process context together provide stronger evidence than either source alone.

Question 384.

Which approach is most effective when investigating suspicious use of a legitimate remote-management utility?

  1. Treat every use of the tool as malicious
    2. Analyze source host, destination, account, command line, parent process, and resulting activity
    3. Ignore it because administrators commonly use such tools
    4. Search only for the executable name

Correct Answer: 2

Explanation:

Remote-management utilities can support legitimate operations or be abused for lateral movement. The hunter should focus on who initiated the activity, from which system, against which destination, and what command or process followed. Parent process and historical usage can provide additional context. Treating the utility as inherently safe or malicious is less effective than evaluating how it was used within the environment.

Question 385.

A Falcon Hunter finds a common executable running from an uncommon path and under an unexpected user account. What should the hunter do first?

  1. Compare the path, hash, signer, parent process, command line, user context, and behavior with legitimate instances
    2. Ignore it because the executable name is common
    3. Delete all events involving that process
    4. Assume every instance of the executable is malicious

Correct Answer: 1

Explanation:

A familiar process running from an unusual path under an unexpected account may indicate masquerading or misuse of legitimate software. The hunter should compare the binary’s hash and signature with known-good versions and examine the process ancestry, command line, user context, and network activity. The combination of path and identity anomalies can provide a stronger signal than executable prevalence alone.

Question 386.

Which pattern most strongly suggests possible command-and-control beaconing?

  1. A user opens a local document
    2. A normal application writes a configuration file
    3. A scheduled backup runs
    4. A process repeatedly contacts the same rare external destination at similar intervals over time

Correct Answer: 4

Explanation:

Repeated outbound communication at consistent intervals can indicate automated beaconing. The hunter should examine the initiating process, destination, interval pattern, DNS activity, affected hosts, and whether communication continues without user interaction. Legitimate software can also communicate periodically, so application purpose and historical baseline should be considered. The behavior becomes more suspicious when paired with unusual execution or persistence.

Question 387.

Which event pattern is most relevant when hunting for security or account discovery behavior?

  1. A normal browser session begins
    2. A routine patch installs
    3. A process repeatedly queries users, groups, privileges, security settings, or account relationships
    4. A user prints a document

Correct Answer: 3

Explanation:

Repeated enumeration of identities, groups, privileges, and security settings can indicate discovery activity. Attackers often collect this information to understand the environment before attempting privilege escalation or lateral movement. The hunter should examine the process, command line, user, parent process, timing, and subsequent behavior. Legitimate administrators may perform similar actions, so operational context remains important.

Question 388.

Which statement best describes the value of grouping search results by execution path?

  1. It proves every unusual path is malicious.
    2. It can expose trusted process names running from unexpected or user-writable locations.
    3. It replaces hash and command-line analysis.
    4. It is useful only for inventory reporting.

Correct Answer: 2

Explanation:

Grouping by execution path can reveal anomalies such as trusted-looking processes running from temporary, user-writable, or otherwise unexpected directories. The hunter can then compare file hashes, signers, command lines, parent processes, and users. This is particularly useful for identifying masquerading or copied tools. Path rarity is a useful hunting signal, but contextual analysis is still needed before determining maliciousness.

Question 389.

A hunter observes an email application launching a scripting engine that writes and executes a file. What should be investigated next?

  1. The email or attachment source, process chain, command line, created file, hash, and subsequent behavior
    2. Only the email application version
    3. Printer settings
    4. Screen resolution

Correct Answer: 1

Explanation:

An email application spawning a scripting engine that creates and executes a file is a suspicious chain that may indicate malicious attachment execution. The hunter should inspect the message or attachment source, process ancestry, command-line arguments, created file, hash, and any resulting network connections. Reconstructing the entire execution chain helps determine how the activity began and whether it is related to broader malicious behavior.

Question 390.

Which behavior most strongly suggests data staging before exfiltration?

  1. A standard application saves a preference file
    2. A browser loads an approved website
    3. A routine update completes
    4. A process locates sensitive documents, copies them to a temporary location, and compresses them into an archive

Correct Answer: 4

Explanation:

Locating sensitive data, consolidating it, and compressing it can indicate staging before exfiltration. The hunter should determine which files were collected, which process and user were involved, where the archive was created, and whether unusual outbound traffic followed. Legitimate backup or migration operations may look similar, so the activity should be compared against known business processes and historical patterns.

Question 391.

Which hunting strategy is most effective when attackers frequently replace tools but retain the same persistence and discovery behaviors?

  1. Search only file hashes
    2. Search only filenames
    3. Hunt for recurring technique patterns, process relationships, and event sequences
    4. Ignore process telemetry

Correct Answer: 3

Explanation:

Behavioral hunting is more durable than relying solely on hashes or filenames. Attackers may replace binaries while continuing to use the same persistence mechanism, discovery activity, or process relationships. Hunters can focus on those behaviors and sequences to identify related activity across changing tools. Static indicators remain valuable for immediate scoping but should complement rather than replace behavioral analysis.

Question 392.

Which statement best describes the value of baselining command-line activity?

  1. It proves every frequent command is safe.
    2. It helps identify rare or unusual arguments that deviate from normal process usage.
    3. It eliminates the need for process-tree analysis.
    4. It automatically blocks suspicious commands.

Correct Answer: 2

Explanation:

Command-line baselines help hunters understand how common applications and utilities are normally invoked. A familiar executable using unusual arguments may deserve investigation even if the process itself is highly prevalent. The hunter should combine this information with parent processes, user context, execution path, and network activity. Baselines prioritize anomalies but do not automatically determine whether they are malicious.

Question 393.

A privileged service account suddenly begins making interactive logons from a user workstation. What should the hunter investigate first?

  1. The source workstation, authentication method, destination systems, timing, and subsequent privileged activity
    2. Only the service account name
    3. Printer configuration
    4. Desktop wallpaper

Correct Answer: 1

Explanation:

Service accounts generally have predictable automated behavior, so interactive use from a user workstation is a significant deviation. The hunter should determine where the logons originated, which systems were accessed, how authentication occurred, and what processes or commands followed. The source workstation should also be examined for credential-access activity. Comparing the event with the account’s intended purpose helps determine whether misuse occurred.

Question 394.

Which behavior most strongly suggests defense evasion through monitoring impairment?

  1. A user launches an approved application
    2. A scheduled maintenance task runs
    3. A routine backup completes
    4. A process disables monitoring controls immediately before executing unfamiliar code

Correct Answer: 4

Explanation:

Disabling monitoring immediately before unfamiliar code executes can indicate an attempt to reduce security visibility. The hunter should identify the process and user responsible for the change, inspect the commands used, and determine what executed during the reduced-monitoring period. Centralized telemetry can be especially useful when local logging or monitoring was affected. Timing is a key factor in establishing whether the actions are related.

Question 395.

A suspicious domain is queried from many endpoints, but only a small subset show related suspicious process activity. What should the hunter do?

  1. Treat every DNS query as confirmed compromise
    2. Ignore the hosts without suspicious processes
    3. Compare requesting processes, users, timestamps, subsequent connections, and behavior across all hosts
    4. Delete the DNS records

Correct Answer: 3

Explanation:

A domain may be contacted for legitimate and malicious reasons, so DNS activity should be interpreted in context. The hunter should compare the processes generating the queries, active users, timing, subsequent connections, and other host behavior. Hosts showing both suspicious process activity and domain communication may deserve higher priority. The comparison can also reveal whether apparently benign systems are part of an earlier or different stage of activity.

Question 396.

Which statement best describes how MITRE ATT&CK can support hunt coverage analysis?

  1. It automatically blocks uncovered techniques.
    2. Mapping existing hunts and detections to techniques can highlight areas where additional hunting coverage may be useful.
    3. It replaces endpoint telemetry.
    4. It proves every uncovered technique is currently being used by an attacker.

Correct Answer: 2

Explanation:

Mapping hunts and detections to ATT&CK techniques can help security teams understand which behaviors receive strong coverage and where gaps may exist. A gap does not mean an attacker is actively using that technique, but it can guide future hypothesis development. ATT&CK provides a structured reference for assessing behavioral coverage while local risk, telemetry, and threat intelligence help determine priorities.

Question 397.

A hunter discovers an approved administrative utility running on an endpoint where its use is not expected. What should be investigated first?

  1. Installation or execution source, user, command line, parent process, destinations, and whether the use is authorized on that endpoint
    2. Ignore it because the utility is approved elsewhere
    3. Assume all instances of the utility are malicious
    4. Delete the endpoint telemetry

Correct Answer: 1

Explanation:

Approved software can still be suspicious when used outside its intended scope. The hunter should determine how the utility appeared, who executed it, what arguments were supplied, which process launched it, and whether it contacted other systems. Asset role and authorization are important contextual factors. Legitimate tools can become effective attacker utilities when used on unexpected systems or by unusual accounts.

Question 398.

Which behavior most strongly suggests possible privilege escalation?

  1. A normal browser launches
    2. An approved application starts
    3. A routine inventory process runs
    4. A standard-user process unexpectedly launches a child process with system-level privileges

Correct Answer: 4

Explanation:

An unexpected transition from standard-user execution to system-level privileges can indicate exploitation or abuse of an elevation mechanism. The hunter should inspect the process ancestry, user identity, command-line arguments, elevation path, and actions performed afterward. Legitimate installers can also create privileged child processes, so software context, signer information, and expected administrative activity should be considered.

Question 399.

Which investigation technique is most useful for determining whether persistence, credential access, and remote execution belong to the same attack chain?

  1. Review only the highest-severity event
    2. Search only one filename
    3. Build a chronological timeline and correlate shared users, hosts, processes, and timestamps
    4. Review only asset inventory

Correct Answer: 3

Explanation:

Chronological correlation helps determine whether different behaviors are related parts of a single intrusion. A timeline can show persistence occurring first, credential access afterward, and remote execution using the affected account later. Shared users, hosts, processes, and timing strengthen the relationship between events. This approach provides a more complete view than analyzing each detection independently.

Question 400.

Which action best completes a threat hunt after the hunter validates malicious activity and identifies a repeatable behavioral pattern?

  1. Delete the findings
    2. Document the evidence, establish scope, support response, and convert the validated pattern into reusable detection or hunting logic
    3. Disable the related telemetry
    4. Leave the behavior undocumented

Correct Answer: 2

Explanation:

A repeatable malicious pattern should be used to improve future defensive coverage. The hunter should document the affected hosts, users, timeline, indicators, and behaviors, then support containment or remediation where needed. Validated hunt logic can be refined into reusable detections or future hunting analytics. This creates a feedback loop in which manual hunting findings strengthen automated and proactive defenses.