View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps
Question 101.
A Falcon Hunter identifies a suspicious executable that launches a command shell and then contacts an uncommon external domain. What should the hunter do first?
- Correlate the process tree, command line, network connection, user context, and related host activity
2. Assume the process is malicious based only on the domain
3. Delete all telemetry from the host
4. Investigate only the executable filename
Correct Answer: 1
Explanation:
The strongest investigation begins by correlating multiple sources of context. The process tree can reveal how the executable started, while command-line data may expose arguments or scripts. Network activity can identify the destination and timing, and user context can show whether the behavior matches expected use. Looking at all of these together helps determine whether the activity represents malware, legitimate administration, or another form of suspicious behavior.
Question 102.
Which behavior is most consistent with persistence through a scheduled task?
- A user opens an approved browser
2. A normal update installs
3. A standard application launches
4. A newly created task repeatedly executes an unfamiliar script at user logon
Correct Answer: 4
Explanation:
A scheduled task configured to execute an unfamiliar script at logon can provide persistence by ensuring that the code runs repeatedly when the user signs in. The hunter should inspect the task creation event, responsible process, user account, script path, command line, and later executions. Legitimate software can also create scheduled tasks, so timing, rarity, signer information, and surrounding behavior should be evaluated before classifying the activity.
Question 103.
Which telemetry is most valuable when investigating possible credential theft from a Windows endpoint?
- Printer status
2. Screen resolution
3. Processes accessing credential-related memory or authentication components
4. Local font settings
Correct Answer: 3
Explanation:
Credential theft commonly involves suspicious interaction with memory or components associated with authentication. The hunter should identify the process involved, its privilege level, parent process, command line, and user context. Follow-on authentication events can help show whether stolen credentials were later used for lateral movement or privilege escalation. Unrelated endpoint configuration data provides little value for this type of investigation.
Question 104.
A hunter receives thousands of results for a suspicious command-line pattern. What is the best way to reduce the data to a manageable set?
- Delete most of the events randomly
2. Aggregate the results by host, user, process, or other meaningful fields
3. Stop the investigation
4. Review only the newest event
Correct Answer: 2
Explanation:
Aggregation helps hunters identify patterns across large data sets. Grouping by host can reveal where the behavior is concentrated, while grouping by user or process can expose common execution paths. Once unusual clusters or outliers are identified, the hunter can drill into the raw events for more detail. This approach is more efficient than manually reviewing every event without prioritization.
Question 105.
A suspicious process appears on several endpoints, but each copy uses a different filename. Which artifact is most useful for determining whether the underlying file is identical?
- Cryptographic file hash
2. Visible filename
3. User display name
4. Hostname only
Correct Answer: 1
Explanation:
If the binary content is unchanged, a cryptographic hash can identify the same file even when it has been renamed. Searching the hash across enterprise telemetry can reveal additional affected systems. The hunter should still combine hash results with behavioral data because attackers may modify the file and generate a different hash. Filename changes alone are easy for adversaries to perform and are therefore a weaker indicator.
Question 106.
Which pattern most strongly suggests possible command-and-control beaconing?
- A user opens an approved document
2. A routine backup starts
3. A system checks for updates once
4. A process repeatedly connects to the same uncommon destination at regular intervals
Correct Answer: 4
Explanation:
Regular, repeated outbound connections to an uncommon destination can indicate beaconing behavior used by command-and-control frameworks. The hunter should inspect the initiating process, interval pattern, destination, affected hosts, and any related DNS activity. Legitimate software can also communicate periodically, so the observed pattern should be compared against normal application behavior and other suspicious telemetry.
Question 107.
Which activity is most useful when investigating suspected lateral movement?
- File compression statistics
2. Browser bookmarks
3. Remote authentication, source and destination hosts, and resulting process execution
4. Printer configuration
Correct Answer: 3
Explanation:
Lateral movement often produces a combination of authentication and remote execution evidence. The hunter should determine where the activity originated, which account was used, which destination system was accessed, and what processes were launched afterward. This sequence helps distinguish legitimate administrative access from malicious movement. Examining only one event type may miss the relationship between access and execution.
Question 108.
Which statement best describes why process ancestry is useful during threat hunting?
- It shows only network information.
2. It helps reveal how suspicious execution started and what processes followed.
3. It proves every child process is malicious.
4. It replaces all other investigation data.
Correct Answer: 2
Explanation:
Process ancestry helps reconstruct the chain of execution surrounding suspicious activity. An unusual parent can suggest exploitation, malicious scripting, or abuse of trusted applications, while child processes can reveal follow-on actions. Process trees should be interpreted alongside command lines, user context, file activity, network connections, and timing. The relationship itself is informative but not automatically proof of maliciousness.
Question 109.
A hunter sees a privileged account launching an unfamiliar executable from a temporary directory. What should the hunter do next?
- Investigate the file, process tree, user activity, command line, and network behavior
2. Ignore the event because the account is privileged
3. Delete the account immediately without analysis
4. Disable all privileged logging
Correct Answer: 1
Explanation:
Unfamiliar execution under a privileged identity can have significant impact and should be investigated carefully. The hunter should examine the executable’s hash and path, parent process, command line, user session, and any network activity. The fact that the account is privileged does not make unusual behavior legitimate. Historical behavior and business context can help distinguish expected administrative actions from compromise.
Question 110.
Which behavior is most suspicious during a hunt for defense evasion?
- A normal application starts
2. A user logs in successfully
3. A scheduled inventory task runs
4. A process disables security monitoring and then clears related logs
Correct Answer: 4
Explanation:
Disabling monitoring and clearing logs are both common defense-evasion behaviors. When they occur together, the activity becomes especially suspicious because an attacker may be attempting to reduce visibility before performing additional actions. The hunter should inspect the responsible process, user context, command line, timing, and any subsequent activity. Remaining telemetry should be preserved to support further investigation.
Question 111.
Which approach is most effective for investigating suspicious activity associated with one user across multiple endpoints?
- Search only the user’s home directory
2. Review only the first host
3. Pivot on the user across authentication, process, and network telemetry
4. Ignore identity events
Correct Answer: 3
Explanation:
Pivoting on the user across several telemetry sources provides a broader view of activity. Authentication logs can show where the account accessed systems, process data can reveal what it executed, and network events can expose suspicious connections. This is especially useful when investigating possible account takeover or lateral movement. A single-host review may miss related behavior occurring elsewhere in the environment.
Question 112.
Which statement best describes the value of rarity during threat hunting?
- Every rare event is malicious.
2. Rare values can be useful hunting leads but must be validated in context.
3. Rare events should always be ignored.
4. Rarity eliminates the need for behavioral analysis.
Correct Answer: 2
Explanation:
Rarity can help prioritize unusual processes, command lines, users, or destinations that deserve investigation. However, rare activity may be perfectly legitimate, such as custom software used by one team. Hunters should combine rarity with other factors such as process ancestry, network behavior, file path, user role, and timing. The strongest hunting conclusions come from multiple supporting signals rather than rarity alone.
Question 113.
A hunter observes a script interpreter launched by an email client shortly after a user opened an attachment. What should be investigated first?
- The process chain, attachment origin, command line, child processes, and network activity
2. Printer settings
3. Only the user’s department
4. Screen resolution
Correct Answer: 1
Explanation:
An email client launching a script interpreter after an attachment is opened can indicate malicious document or attachment execution. The hunter should inspect the full process tree, attachment source, command line, child processes, file creation, and outbound connections. This sequence is suspicious but still requires validation because some legitimate workflows may invoke scripting. Timing and surrounding context are important.
Question 114.
Which behavior most strongly suggests data staging before exfiltration?
- A user opens a browser
2. A normal system update runs
3. A local application writes a small log file
4. A process collects files from several locations and compresses them into a large archive
Correct Answer: 4
Explanation:
Attackers often collect and compress data before transferring it out of the environment. A large archive created from many files or directories can therefore be a useful staging indicator, especially if followed by unusual outbound traffic. The hunter should inspect the source files, archive location, responsible process, user context, and subsequent network activity. Legitimate backup and administrative operations should also be considered.
Question 115.
Which hunting method is most resilient when attackers frequently change filenames, hashes, and domains?
- Search only exact indicators
2. Search only filenames
3. Hunt for recurring behavioral patterns and event sequences
4. Ignore command-line activity
Correct Answer: 3
Explanation:
Behavioral hunting focuses on how an attacker operates rather than on indicators that can be changed easily. Process ancestry, command-line structures, persistence methods, network patterns, and event sequences are often more durable than filenames or hashes. Static indicators remain useful, but behavioral analytics help detect adversaries even when they modify individual tools or infrastructure.
Question 116.
Which statement best describes the purpose of hypothesis-driven hunting?
- It requires the hunter to know the exact malware sample in advance.
2. It starts with a testable assumption about attacker behavior and evaluates it using available telemetry.
3. It avoids using threat intelligence.
4. It guarantees malicious activity will be found.
Correct Answer: 2
Explanation:
Hypothesis-driven hunting begins with a specific idea about adversary behavior, environmental risk, or a potential detection gap. The hunter identifies the necessary telemetry and constructs searches to determine whether the evidence supports the hypothesis. A hunt can still be valuable even if no malicious activity is found because it may validate controls, improve baselines, or reveal gaps in visibility.
Question 117.
A suspicious domain is found on one endpoint. Which action best helps determine enterprise scope?
- Search the domain across telemetry and identify associated hosts, processes, users, and timestamps
2. Search only the original host
3. Delete the network event
4. Ignore the initiating process
Correct Answer: 1
Explanation:
Searching the domain across enterprise telemetry can reveal whether multiple hosts contacted it and which processes were responsible. The hunter can then correlate users, timing, command lines, DNS events, and other indicators. This helps determine whether the activity is isolated or part of a broader campaign. External reputation is useful, but local context is necessary to understand how the domain was used.
Question 118.
Which behavior most strongly suggests possible privilege escalation?
- A user opens an approved application
2. A routine maintenance process runs
3. An inventory scan completes
4. A low-privilege process unexpectedly spawns a process running with elevated rights
Correct Answer: 4
Explanation:
An unexpected privilege transition can indicate exploitation or abuse of an elevation mechanism. The hunter should inspect the process ancestry, account, command line, privilege level, and subsequent activity. Legitimate installers and administrative tools may also elevate privileges, so context and baseline behavior are important. Unexpected elevation followed by credential access or system modification would increase the level of concern.
Question 119.
Which investigation technique is most useful for understanding the sequence of attacker actions on a single host?
- Reviewing only detection severity
2. Searching only one file hash
3. Building a timeline of process, file, network, and authentication events
4. Reviewing only the host’s inventory
Correct Answer: 3
Explanation:
A timeline shows how suspicious activity developed over time and can reveal initial execution, persistence, credential access, network communication, and follow-on actions. Temporal relationships often provide insights that isolated events do not. Timelining is especially valuable when reconstructing what happened immediately before and after a detection and identifying previously overlooked stages of an intrusion.
Question 120.
Which action best completes a threat hunt after malicious behavior has been confirmed?
- Delete all supporting evidence
2. Document findings, determine scope, support response, and improve future detections or hunting analytics
3. Stop collecting related telemetry
4. Leave the hunt undocumented
Correct Answer: 2
Explanation:
A completed hunt should contribute to both immediate response and long-term defensive improvement. The hunter should document affected hosts, users, timelines, behaviors, and relevant indicators, then coordinate containment or remediation where necessary. Useful queries and behavioral patterns can be converted into reusable detections or future hunt logic. Lessons learned can also identify telemetry gaps and improve the organization’s overall hunting process.