CCFH-202 Actual Exam Questions

Last updated on Feb. 23, 2025.
Vendor:CrowdStrike
Exam Code:CCFH-202
Exam Name:CrowdStrike Certified Falcon Hunter
Exam Questions:88
 

Topic 1 - Exam A

Question #1 Topic 1

Which of the following is a suspicious process behavior?

  • A. PowerShell running an execution policy of RemoteSigned
  • B. An Internet browser (eg., Internet Explorer) performing multiple DNS requests
  • C. PowerShell launching a PowerShell script
  • D. Non-network processes (e.g., notepad.exe) making an outbound network connection
Reveal Solution Hide Solution   Discussion   4

Correct Answer: D 🗳️

Question #2 Topic 1

Which field should you reference in order to find the system time of a *FileWritten event?

  • A. ContextTimeStamp_decimal
  • B. FileTimeStamp_decimal
  • C. ProcessStartTime_decimal
  • D. timestamp
Reveal Solution Hide Solution   Discussion   6

Correct Answer: A 🗳️

Question #3 Topic 1

What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?

  • A. Hash Search
  • B. IP Search
  • C. Domain Search
  • D. User Search
Reveal Solution Hide Solution   Discussion   4

Correct Answer: D 🗳️

Question #4 Topic 1

An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host. What is this type of analysis called?

  • A. Visualization of hosts
  • B. Statistical analysis
  • C. Temporal analysis
  • D. Machine Learning
Reveal Solution Hide Solution   Discussion   1

Correct Answer: C 🗳️

file Viewing page 1 out of 22 pages.
Viewing questions 1-4 out of 88 questions
Next Questions
Browse atleast 50% to increase passing rate cup
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago