{"id":24810,"date":"2026-09-30T06:00:14","date_gmt":"2026-09-30T06:00:14","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24810"},"modified":"2026-09-30T06:00:14","modified_gmt":"2026-09-30T06:00:14","slug":"crowdstrike-ccfh-202b-test-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/crowdstrike-ccfh-202b-test-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"CrowdStrike CCFH-202b Test Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ccfh-202b-exam-dumps\"><b>CrowdStrike CCFH-202b Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 341.<\/b><\/p>\n<p><b>A Falcon Hunter identifies a suspicious executable that appears on several hosts but is launched by different parent processes. What should the hunter investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compare the hash, paths, command lines, users, parent processes, and follow-on activity across all affected hosts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the first host where the file appeared<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore the parent-process differences<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete all related telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing the same executable across multiple hosts helps determine whether the activity represents a common deployment, malware distribution, or separate unrelated events. Differences in parent processes can reveal different execution paths or delivery methods. The hunter should compare file hashes, paths, command lines, users, timestamps, network connections, and child processes. Cross-host analysis provides a stronger picture of scope and behavior than examining a single endpoint in isolation.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>Which behavior most strongly suggests persistence through modification of an existing service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a normal browser<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled inventory task executes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A routine software patch installs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A service&#8217;s executable path is changed to launch an unfamiliar binary at system startup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Changing an existing service so that it launches an unfamiliar binary can provide persistence and may help malicious activity blend with trusted system components. The hunter should identify the process and account responsible for the modification, review the new binary, and examine subsequent service starts. Legitimate software upgrades can also modify services, so timing, signer information, and deployment records should be considered during validation.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>Which telemetry is most useful when investigating suspicious remote execution associated with a privileged account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Desktop wallpaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Source host, destination host, authentication events, privileged account activity, and resulting processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Installed fonts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote execution involving a privileged identity should be analyzed by correlating authentication and endpoint telemetry. The hunter should determine where the connection originated, which destination was accessed, how the account authenticated, and what processes or commands executed afterward. Privileged accounts can perform legitimate remote administration, so historical usage, source systems, timing, and business context are important for distinguishing expected behavior from compromise.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>Which approach is most effective when a hunter sees suspicious execution of a legitimate signed binary?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume the binary is safe because it is signed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Examine the command line, process ancestry, user context, path, and resulting behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore all signed software during hunts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Search only the executable name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature can establish software provenance but does not guarantee that every use of the program is legitimate. Attackers may abuse signed utilities for execution, discovery, or defense evasion. The hunter should examine how the binary was launched, the command-line arguments, its parent process, user, location, and follow-on activity. Behavioral context is therefore essential even when the executable itself is trusted.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>A Falcon Hunter sees an executable with high prevalence but only one host uses an unusual command-line argument. What should the hunter do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigate the unusual command line, parent process, user context, and subsequent activity on that host<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the event because the executable is common<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all events involving the executable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume all executions are malicious<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High prevalence does not mean every execution is benign. A common executable may be abused with unusual arguments or launched in an unexpected context. The hunter should compare the anomalous command line with normal instances, then review the parent process, user, path, file activity, and network behavior. The deviation from baseline may be more significant than the prevalence of the executable itself.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>Which pattern most strongly suggests possible command-and-control traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a local application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A normal backup completes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A routine update checks for patches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A process repeatedly communicates with a rare destination at regular intervals while the user is inactive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regular outbound communication to an uncommon destination, especially when no user is active, can indicate automated command-and-control behavior. The hunter should review the process responsible, interval pattern, destination, DNS activity, and whether similar behavior exists on other endpoints. Legitimate services may also communicate in the background, so software purpose and historical baseline should be considered before determining maliciousness.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>Which event pattern is most relevant when hunting for network discovery activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a document<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A browser connects to an approved website<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A process repeatedly enumerates network interfaces, routes, neighboring systems, or reachable resources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A printer job completes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated enumeration of network configuration and reachable systems can indicate network discovery. Attackers often perform discovery before choosing lateral-movement targets. The hunter should examine the process, command line, user, parent process, timing, and whether remote authentication or scanning activity follows. Administrators may perform similar actions, so the host role and user context should also be evaluated.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>Which statement best describes the value of grouping events by command-line arguments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It proves every rare argument is malicious.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It can reveal uncommon execution patterns and repeated behaviors that differ from normal usage.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need to review parent processes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It is useful only for software inventory.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Grouping by command-line arguments can expose rare or recurring usage patterns that would be difficult to notice in raw event data. A commonly used process may have one unusual argument set associated with suspicious hosts. The hunter can then drill into parent processes, users, paths, and network activity. Command-line grouping helps prioritize investigation but does not by itself establish malicious intent.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>A hunter observes a browser spawning a utility that retrieves a remote file and then launches it. What should be investigated next?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The browser activity, process chain, retrieval command, downloaded file, destination, and subsequent execution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the browser version<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Screen brightness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A browser spawning a utility that retrieves and executes a remote file is a suspicious chain that may indicate exploitation or user-assisted malware delivery. The hunter should reconstruct the process sequence, identify the retrieval source, review the downloaded file&#8217;s hash and path, and inspect what happened after execution. Correlating these events can help determine whether the behavior is isolated or part of a larger campaign.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>Which behavior most strongly suggests data staging before exfiltration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a standard application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A normal service writes a log file<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A routine update completes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A process enumerates sensitive files, copies selected data to a temporary folder, and creates an archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enumeration, collection, and compression of sensitive data can indicate staging before exfiltration. The hunter should determine which files were gathered, the process and account involved, the archive destination, and whether unusual outbound traffic followed. Legitimate backup or migration workflows may create similar patterns, so the behavior should be compared with known business operations and historical activity.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>Which hunting strategy is most effective when adversaries regularly change hashes and domains but reuse the same sequence of discovery, persistence, and execution behaviors?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search only known hashes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Search only known domains<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hunt for the recurring behavior chain and associated process relationships<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore process telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavior chains are more durable than individual indicators because attackers can change hashes and infrastructure quickly. Repeated discovery, persistence, and execution patterns may remain recognizable across variants. Hunters should focus on those techniques, process relationships, and event sequences while still using known indicators for immediate scoping. This approach improves coverage against evolving attacker tooling.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>Which statement best describes the value of baselining privileged-account activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It proves all common privileged actions are legitimate.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It helps identify unusual source hosts, destinations, times, and administrative behaviors.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for event review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It automatically blocks anomalous activity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged accounts often have recognizable patterns of systems, tools, and working hours. Establishing a baseline helps identify deviations such as access from unusual workstations, unexpected servers, or unfamiliar commands. An anomaly does not automatically indicate compromise, but it provides a useful lead. Because privileged accounts can have broad impact, unusual behavior should be investigated carefully.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>A privileged account begins logging in from a user workstation instead of its normal administrative jump host. What should the hunter investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source workstation, authentication method, destination systems, timing, and resulting privileged actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the account name<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer queue activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Desktop theme<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A privileged account authenticating from an unexpected workstation may indicate credential theft, policy bypass, or a legitimate exception. The hunter should determine how the account authenticated, which systems it accessed, and what privileged actions followed. The source workstation should also be checked for suspicious process or credential activity. Comparing the event with historical account behavior can help determine whether the deviation is authorized.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>Which behavior most strongly suggests defense evasion through security configuration changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens an approved application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A normal software update runs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A scheduled backup completes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A process modifies security exclusions and disables monitoring before launching an unfamiliar executable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Changing exclusions and disabling monitoring immediately before launching unfamiliar code strongly suggests an attempt to evade security controls. The hunter should inspect the process responsible, account, command line, parent process, and any subsequent activity. The timing between the configuration changes and executable launch is especially important. Centralized telemetry may preserve evidence even if local monitoring was impaired.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>A suspicious domain appears in DNS queries across multiple hosts, but only some hosts make outbound connections. What should the hunter do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat every DNS query as confirmed compromise<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore hosts that did not connect<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compare the requesting processes, users, timestamps, connection attempts, and host context across all systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete all DNS events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A DNS request does not necessarily mean a successful connection or malicious activity. The hunter should compare which process made the request, whether a connection followed, which user was active, and how the hosts differ. This can reveal blocked communications, legitimate lookups, or varying stages of suspicious activity. Cross-host comparison helps avoid overinterpreting DNS telemetry in isolation.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>Which statement best describes how ATT&amp;CK can help identify investigative gaps?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It automatically detects missing telemetry.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Mapping observed techniques can highlight related tactics or behaviors for which the hunter has not yet searched.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces the need for endpoint data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It proves all mapped activity is malicious.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mapping observed behavior to ATT&amp;CK can reveal logical gaps in an investigation. For example, if the hunter finds credential access and lateral movement but has not examined persistence, the framework may suggest additional areas to search. ATT&amp;CK supports systematic thinking and consistent terminology, but the hunter still needs local telemetry to determine whether related techniques actually occurred.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>A hunter finds an approved administrative tool running on a system where it is not normally installed. What should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Installation source, execution path, user, command line, destinations, and whether the use is authorized on that system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore it because the tool is approved somewhere in the organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume all use of the tool is malicious<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the host telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software approval does not mean the tool is expected on every asset. The hunter should determine how it appeared on the system, who executed it, what commands were used, and which destinations it contacted. Asset role and software distribution policy provide important context. Unexpected deployment of legitimate administration software can indicate misuse or unauthorized remote access.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>Which behavior most strongly suggests privilege escalation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user launches a normal browser<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled inventory task runs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An approved application opens<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A low-privilege process unexpectedly causes execution under a highly privileged system account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unexpected transition from a low-privilege process to a highly privileged system context can indicate privilege escalation. The hunter should examine process ancestry, user identity, command-line arguments, the elevation mechanism, and actions performed afterward. Legitimate software installations may also elevate privileges, so signer information, deployment context, and historical behavior should be considered.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>Which investigation technique is most useful for determining whether discovery activity led to lateral movement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review only the discovery command<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Search only the source hostname<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Build a timeline that correlates discovery, authentication, remote access, and resulting process activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Review only asset inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A timeline can show whether discovery was followed by authentication to identified systems and then by remote process execution. This helps establish whether separate events form one attack sequence. Correlating users, hosts, processes, and timestamps provides stronger evidence than reviewing the discovery event by itself. Timelining is particularly useful for understanding progression across multiple stages of an intrusion.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>Which action best completes a hunt after the hunter identifies and validates a new attack pattern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the investigation notes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Document the pattern, establish scope, coordinate response, and improve reusable detection or hunting analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable the associated telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Leave the findings undocumented<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A validated attack pattern should improve both immediate response and future detection capability. The hunter should document affected hosts, users, timelines, indicators, and behaviors, then coordinate containment or remediation where appropriate. The confirmed pattern can be translated into new or improved detection logic and reusable hunting analytics, allowing similar activity to be identified more efficiently in the future.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CrowdStrike CCFH-202b Exam Dumps and Practice Test Dumps &nbsp; Question 341. A Falcon Hunter identifies a suspicious executable that appears on several hosts but is launched by different parent processes. What should the hunter investigate first? Compare the hash, paths, command lines, users, parent processes, and follow-on activity across all affected hosts 2. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24810"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24810"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24810\/revisions"}],"predecessor-version":[{"id":24811,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24810\/revisions\/24811"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24810"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24810"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24810"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}