CCFH-202B Exam Questions
87 real CCFH-202B exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which of the following would be the correct field name to find the name of an event?
- Question #2
Event Search data is recorded with which time zone?
- Question #4
How do you rename fields while using transforming commands such as table, chart, and stats?
- Question #5
SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time. Which eval function is correct?
- Question #6
Which of the following queries will return the parent processes responsible for launching badprogram exe?
- Question #7
You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?
- Question #8
When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName
- Question #9
Which tool allows a threat hunter to populate and colorize all known adversary techniques in a single view?
- Question #10
Which of the following is an example of actor actions during the RECONNAISSANCE phase of the Cyber Kill Chain?
- Question #11
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?
- Question #12
In the MITRE ATT&CK Framework (version 11 - the newest version released in April 2022), which of the following pair of tactics is not in the Enterprise: Windows matrix?
- Question #13
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
- Question #14
What information is provided from the MITRE ATT&CK framework in a detection's Execution Details?
- Question #15
You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?
- Question #16
The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because:
- Question #17
Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
- Question #18
What topics are presented in the Hunting and Investigation Guide?
- Question #19
Which of the following does the Hunting and Investigation Guide contain?
- Question #20
Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connection...
- Question #21
What is the main purpose of the Mac Sensor report?
- Question #22
Where would an analyst find information about shells spawned by root, Kernel Module loads, and wget/curl usage?
- Question #23
Which of the following best describes the purpose of the Mac Sensor report?
- Question #24
In the Powershell Hunt report, what does the "score" signify?
- Question #25
In the Powershell Hunt report, what does the filtering condition of commandLine! ="*badstring* " do?
- Question #26
What Investigate tool would you use to allow an analyst to view all events for a specific host?
- Question #27
What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?
- Question #28
What elements are required to properly execute a Process Timeline?
- Question #29
What information is provided when using IP Search to look up an IP address?
- Question #30
What kind of activity does a User Search help you investigate?
- Question #31
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, expand and refer to the _______dashboard panel.
- Question #32
When performing a raw event search via the Events search page, what are Event Actions?
- Question #33
What information is shown in Host Search?
- Question #34
You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each doma...
- Question #35
Which field in a DNS Request event points to the responsible process?
- Question #36
Which of the following is a suspicious process behavior?
- Question #37
Which field should you reference in order to find the system time of a *FileWritten event?
- Question #38
What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
- Question #39
An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host. What is this type of analysis ca...
- Question #40
Refer to Exhibit. Falcon detected the above file attempting to execute. At initial glance, what indicators can we use to provide an initial analysis of the file?
- Question #41
A benefit of using a threat hunting framework is that it:
- Question #42
Which of the following is an example of a Falcon threat hunting lead?
- Question #43
The Falcon Detections page will attempt to decode Encoded PowerShell Command line parameters when which PowerShell Command line parameter is present?
- Question #44
Which structured analytic technique contrasts different hypotheses to determine which is the best leading (prioritized) hypothesis?
- Question #45
Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?
- Question #46
What is the difference between a Host Search and a Host Timeline?
- Question #47
The Process Timeline Events Details table will populate the Parent Process ID and the Parent File columns when the cloudable Event data contains which event field?
- Question #48
While you're reviewing Unresolved Detections in the Host Search page, you notice the User Name column contains "hostnameS". What does this User Name indicate?
- Question #49
Which of the following is TRUE about a Hash Search?
- Question #50
With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of the following outlines...
- Question #51
The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against y...