Crowdstrike Certified Falcon Hunter Free Sample Questions

20 free sample questions218 in the full practice test

Try simulator

CCFH-202 Sample Questions

  1. Question 1

    A threat hunter is investigating a custom-compiled variant of Mimikatz. The malicious binary was executed on a single host and immediately deleted by the adversary. No file hash is available. Which Falcon search feature is the most effective starting point to identify other hosts where this specific binary may have been executed?

    Answer and explanation

    Correct answer: D

    Even if a file is deleted from the disk, CrowdStrike Falcon captures the hash of any process at the time of execution and records it within the ProcessRollup2 event. A threat hunter can extract this SHA256 hash and use the global Hash Search feature to find every other instance where that exact binary was executed across the entire environment, regardless of its filename or if it was subsequently deleted.

  2. Question 2

    A security analyst is building a CQL query to identify potential DNS tunneling activity. The goal is to find hosts making an unusually high number of DNS requests for subdomains of a single parent domain. Which combination of CQL functions is best suited for this task?

    Answer and explanation

    Correct answer: C

    This query correctly identifies DNS tunneling by first filtering for DNS request events. It then uses the rex command with a regular expression to extract the root domain (e.g., 'example.com' from 'a.b.c.example.com'). Finally, it uses stats to calculate the distinct count (dc) of unique full DomainName values, grouping them by the agent ID (aid) and the extracted root_domain. A high subdomain_count for a single root_domain on a specific host is a strong indicator of DNS tunneling.

  3. Question 3

    During an investigation, a hunter analyzes a process tree where winword.exe spawns cmd.exe, which in turn launches powershell.exe. In the context of Falcon event data, what are the respective process relationships of cmd.exe?

    Answer and explanation

    Correct answer: B

    In the Falcon event model, the 'Parent Process' is the process that created the event's target. The 'Target Process' is the process on which the action occurred. In the event where cmd.exe launches powershell.exe, cmd.exe is the Parent Process and powershell.exe is the Target Process. In the preceding event where winword.exe launched cmd.exe, winword.exe was the Parent Process.

  4. Question 4

    Multiple answers

    A threat hunter is developing a hypothesis that adversaries are using a specific living-off-the-land binary (LOLBAS), certutil.exe, to download payloads from the internet. Which of the following activities, when combined, provide the strongest evidence to validate this hypothesis? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The certutil.exe binary is not expected to make network connections during its normal certificate management functions. An outbound network connection is highly anomalous and directly supports the hypothesis of it being used to download files.

    These specific command-line arguments are used with certutil.exe to fetch a file from a URL and save it to the local disk. Their presence is a key indicator that the tool is being used for file download purposes, which is a common TTP for adversaries.

  5. Question 5

    A hunter observes a detection for PowerShell executing a command containing -e followed by a long, seemingly random string of characters. The Falcon UI automatically decodes this string. This behavior is most indicative of which MITRE ATT&CK technique?

    Answer and explanation

    Correct answer: B

    The -e or -encodedcommand parameter in PowerShell accepts a base64-encoded string. Adversaries use this to hide their commands from simple keyword-based detection and logging. This is a classic example of T1027: Obfuscated Files or Information, specifically sub-technique T1027.010 Command and Scripting Obfuscation.

  6. Question 6

    True or False: The stats command in CQL can only be used to count events and cannot calculate other mathematical aggregations like averages or sums.

    Answer and explanation

    Correct answer: B

    The stats command is a powerful aggregation tool in CQL. In addition to count, it supports various other functions, including avg() for average, sum() for sum, min() for minimum, max() for maximum, dc() for distinct count, and values() to list distinct values.

  7. Question 7

    A pharmaceutical company is investigating a potential data exfiltration incident. The primary suspect is a disgruntled scientist who recently left the company. The security team believes the scientist may have used a cloud storage synchronization client to upload proprietary research data from their corporate laptop just before their departure.

    The security team has the scientist's laptop under forensic hold but first wants to use Falcon to quickly scope the activity across the environment. The known information is the name of a common cloud sync application (megasync.exe), the user's account name (j.doe), and the timeframe of the activity (the last 48 hours before the account was disabled).

    The goal is to create a report for management that visualizes the volume of outbound data per host associated with this user and application, to prioritize which other machines might have been compromised or used for exfiltration.

    Which approach in Falcon would most efficiently achieve this goal?

    Answer and explanation

    Correct answer: D

    This is the most direct and efficient method. The CQL query precisely targets the exfiltration activity by filtering for outbound network events (NetworkSend) from the specific application and user. Using stats sum(bytes_sent) by ComputerName aggregates the total data sent from each host, directly answering the core investigative question. Saving this to a custom dashboard provides a clear visualization (like a bar chart) that is perfect for management reporting and prioritizing the investigation on the hosts with the highest exfiltration volumes.

  8. Question 8

    A hunter needs to create a CQL query that finds all FileWritten events but excludes any writes to files with .log or .tmp extensions. What is the correct syntax to achieve this?

    Answer and explanation

    Correct answer: D

    This query correctly uses the search command with the NOT operator to exclude results. The IN operator allows for checking against a list of values. By combining NOT and IN, the query efficiently filters out any FileWritten events where the FileName ends in either .log or .tmp. The wildcards * are also correctly used to match any filename.

  9. Question 9

    When analyzing a Host Timeline, a threat hunter needs to understand the state of the host at a specific point in time, including running processes and network connections. Which built-in Falcon feature, accessible from the Host Management page, provides this detailed point-in-time snapshot?

    Answer and explanation

    Correct answer: C

    The Host Snapshot feature provides a detailed point-in-time forensic capture of a host's state. This includes a list of running processes, active network connections, loaded drivers, and other critical system information. It is the designated tool for obtaining a comprehensive snapshot for deep analysis without needing a full Real Time Response session.

  10. Question 10

    A hunter is investigating an alert where lsass.exe crashed on a domain controller. The hypothesis is that an attacker attempted to dump credentials. To find the process that interacted with lsass.exe just before the crash, what is the most precise event to search for?

    Answer and explanation

    Correct answer: C

    Credential dumping tools work by opening a handle to the lsass.exe process and reading its memory. The ProcessAccess event is specifically designed to capture this activity, logging when one process (SourceImageFileName) attempts to access another (TargetImageFileName). Searching for ProcessAccess events where lsass.exe is the target is the most direct way to identify the culprit process.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 218 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon