Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by CrowdStrike
Exam Format
Registration
Validity
CCFH-202 Exam Topics and Domains
CCFH-202 is organized into 7 weighted domains. Expect to work with Falcon Console, Activity Classification, Advanced Event Search, Analysis Interface, and more.
MITRE ATT&CK Frameworks
Cyber Kill Chain Knowledge
Demonstrate knowledge of the cyber kill chain and recognize intelligence gaps
MITRE ATT&CK Framework Application
Utilize the MITRE ATT&CK Framework to model threat actor behaviors
ATT&CK Framework Operationalization
Operationalize the MITRE ATT&CK Framework to research threat models and convey to non-technical audiences
Detection Analysis
Host Timeline Analysis
Analyze information displayed in the Host Timeline to understand host states and events
Process Timeline Analysis
Analyze the information displayed in the Process Timeline to understand the flow of events and detections
Investigation Pivoting
Pivot from the detection page to additional investigative tools
Search and Investigation Tools
File and Process Metadata
Analyze and interpret metadata around files and processes recorded by Falcon
Investigate Module Tools
Differentiate use of Investigate Module tools available in Falcon
Search Options
Understand use cases for various search options
Dashboard Interpretation
Interpret search result information displayed in dashboards to determine additional investigation or action
Event Search
CrowdStrike Query Language (CQL)
Define key syntax of CrowdStrike Query Language (CQL)
Query Building and Execution
- Build a query and perform a search using CQL
- Construct simple and complex EAM queries in Falcon
Event Data Formatting
- Format event data for user readability, export or charting
- Convert and format Unix times to UTC readable time
Event Data Analysis
Filter event data and analyze results
Process Relationships
- Describe the process relationship of (Target/Parent/Context)
- Investigate a process tree
Event Types and Dictionary
- Define key data event types
- Explain what information is in the Events Data Dictionary
Custom Dashboards
Create a custom dashboard to display Advanced Event Search results
Reports and References
Hunt Reports
- Use the built-in Hunt reports to refine event details
- Locate built-in Hunting reports and explain what they provide
Visibility Reports
Use the built-in Visibility reports to refine event details
Events Documentation
Leverage the Events Full Reference documentation to learn information about specific events
Hunting Analytics
Malicious Behavior Recognition
Analyze and recognize suspicious overt malicious behaviors
Target System Understanding
Understand target systems (asset inventory and who would target those assets)
Information Evaluation
Evaluate information for reliability, validity and relevance for use in the process of elimination
False Positive Reduction
Identify alternative analytical interpretations to minimize and reduce false positives
Script Analysis
Decode and understand PowerShell/CMD activity
Pattern Recognition
Recognize patterns such as an enterprise-wide file infection process to determine the root cause or source of the infection
Behavior Differentiation
Differentiate testing, DevOps or general user activity from adversary behavior
Vulnerability Identification
Identify the vulnerability exploited from an initial attack vector
Hunting Methodology
Active Hunt Operations
Conduct routine active hunt operations within your environment to determine if your environment has been breached
Outlier Analysis
Perform outlier analysis with the Falcon tool
Hypothesis-Driven Hunting
Conduct hypothesis and hunting lead generation to prove them using Falcon tools
How do I earn this certification?
Passing CCFH-202 earns the CrowdStrike Certified Falcon Hunter certification. It sits in the CrowdStrike Security Operations track.
- CCFA-200 - CrowdStrike Certified Falcon AdministratorFoundation platform management skills
- CCFR-201 - CrowdStrike Certified Falcon ResponderAdvanced incident response capabilities
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for CCFH-202 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2025-01-14
- CrowdStrike Query Language (CQL) Latest Core competency - 20% of exam content • Release date: Ongoing updates
- Falcon Insight EDR Latest Detection and response capabilities central to exam • Release date: Continuous updates
- MITRE ATT&CK Integration Latest Framework Framework understanding required - 15% of exam • Release date: Regular updates
Who should take this exam?
This exam is typically taken by SOC Analysts and Threat Hunters.
- At least 6 months of experience with CrowdStrike Falcon in a production environment
- Completion of CrowdStrike Certified Falcon Hunter courses in CrowdStrike University
- Experience with threat hunting and incident response
- Knowledge of MITRE ATT&CK Framework