CCFH-202B Exam Questions
87 real CCFH-202B exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Event Search and Query Fundamentals
Which of the following would be the correct field name to find the name of an event?
field naming conventionsevent_simpleNameEvent SearchFalcon data fields - Question #2Event Search and Query Fundamentals
Event Search data is recorded with which time zone?
UTCtime zonesEvent Searchdata recording - Question #4Event Search and Query Fundamentals
How do you rename fields while using transforming commands such as table, chart, and stats?
rename commandstats commandtransforming commandsSPL - Question #5Event Search and Query Fundamentals
SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time. Which eval function is correct?
strftimeeval functionUnix epoch timetime conversion - Question #6Threat Hunting with Event Search
Which of the following queries will return the parent processes responsible for launching badprogram exe?
parent processsub-searchProcessRollup2process hunting - Question #7Event Search and Query Fundamentals
You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?
table commandSPL commandsfield selectionEvent Search - Question #8Event Search and Query Fundamentals
When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName
export resultsStatistics tabVerbose Modetransforming commands - Question #9Threat Intelligence Frameworks
Which tool allows a threat hunter to populate and colorize all known adversary techniques in a single view?
MITRE ATT&CK Navigatorthreat visualizationadversary techniquesthreat hunting tools - Question #10Threat Intelligence Frameworks
Which of the following is an example of actor actions during the RECONNAISSANCE phase of the Cyber Kill Chain?
Cyber Kill ChainReconnaissance phasethreat actor behaviorattack lifecycle - Question #11Threat Intelligence Frameworks
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?
MITRE ATT&CKthreat frameworksadversary tacticsthreat intelligence - Question #12Threat Intelligence Frameworks
In the MITRE ATT&CK Framework (version 11 - the newest version released in April 2022), which of the following pair of tactics is not in the Enterprise: Windows matrix?
MITRE ATT&CKEnterprise Windows matrixtacticsATT&CK v11 - Question #13Threat Intelligence Frameworks
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
Cyber Kill ChainWeaponization phaseattack lifecycleactor-victim interaction - Question #14Threat Intelligence Frameworks
What information is provided from the MITRE ATT&CK framework in a detection's Execution Details?
MITRE ATT&CKTechnique IDFalcon detectionsexecution details - Question #15Falcon Platform Documentation and Resources
You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?
Events Data DictionaryFalcon documentationsensor eventsdata fields - Question #16Falcon Platform Documentation and Resources
The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because:
Events Data DictionaryFalcon documentationEvent Search referencehunting queries - Question #17Falcon Platform Documentation and Resources
Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
Hunting and Investigation Guidescheduled tasksWindows artifactsFalcon documentation - Question #18Falcon Platform Documentation and Resources
What topics are presented in the Hunting and Investigation Guide?
Hunting and Investigation Guidesample queriesbest practicesFalcon documentation - Question #19Falcon Platform Documentation and Resources
Which of the following does the Hunting and Investigation Guide contain?
Hunting and Investigation Guideexample queriesEvent Searchthreat hunting - Question #20Falcon Platform Documentation and Resources
Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connection...
Hunting and Investigation GuideSplunk hunting queriesbest practicespredefined queries - Question #21Falcon Platform Reporting
What is the main purpose of the Mac Sensor report?
Mac Sensor reporthost activity monitoringFalcon reporting - Question #22Falcon Platform Reporting
Where would an analyst find information about shells spawned by root, Kernel Module loads, and wget/curl usage?
Linux Sensor reportshell activitykernel module loadswget/curl usage - Question #23Falcon Platform Reporting
Which of the following best describes the purpose of the Mac Sensor report?
Mac Sensor reporthost activity monitoringFalcon reporting - Question #24Threat Hunting and Investigation
In the Powershell Hunt report, what does the "score" signify?
PowerShell Hunt reportcommand line switchesmaliciousness scoring - Question #25Threat Hunting and Investigation
In the Powershell Hunt report, what does the filtering condition of commandLine! ="*badstring* " do?
PowerShell Hunt reportcommand line filteringquery syntax - Question #26Falcon Investigate Tools
What Investigate tool would you use to allow an analyst to view all events for a specific host?
Host TimelineInvestigate toolsevent investigation - Question #27Falcon Investigate Tools
What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?
Process TimelineHash SearchFalcon navigation - Question #28Falcon Investigate Tools
What elements are required to properly execute a Process Timeline?
Process TimelineAgent IDTarget Process IDrequired parameters - Question #29Falcon Investigate Tools
What information is provided when using IP Search to look up an IP address?
IP Searchinternal IPsexternal IPsnetwork investigation - Question #30Falcon Investigate Tools
What kind of activity does a User Search help you investigate?
User Searchprocess activityuser account investigation - Question #31Falcon Investigate Tools
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, expand and refer to the _______dashboard panel.
Host Searchremovable mediasuspicious file activitydashboard panels - Question #32Falcon Investigate Tools
When performing a raw event search via the Events search page, what are Event Actions?
Event SearchEvent Actionspivotable workflowsraw event search - Question #33Falcon Investigate Tools
What information is shown in Host Search?
Host Searchprocesses and serviceshost information - Question #34Threat Hunting and Investigation
You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each doma...
Bulk Domain Searchdomain investigationacceptable use policytool selection - Question #35Event Data Analysis
Which field in a DNS Request event points to the responsible process?
DNS Request eventsContextProcessId_readableevent field mapping - Question #36Threat Detection and Analysis
Which of the following is a suspicious process behavior?
suspicious process behaviornon-network processesoutbound connectionsbehavioral analysis - Question #37Event Data Analysis
Which field should you reference in order to find the system time of a *FileWritten event?
FileWritten eventsContextTimeStamp_decimalevent field mappingtimestamp fields - Question #38Threat Hunting and Investigation
What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
User Searchthreat huntingadversary differentiationDevOps activity - Question #39Threat Hunting and Investigation
An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host. What is this type of analysis ca...
temporal analysisdetection sortingfirst victim identificationanalysis methodology - Question #40Threat Detection and Analysis
Refer to Exhibit. Falcon detected the above file attempting to execute. At initial glance, what indicators can we use to provide an initial analysis of the file?
file analysislocal/global prevalenceVirusTotal pivotsinitial triage indicators - Question #41Threat Hunting Fundamentals
A benefit of using a threat hunting framework is that it:
threat hunting frameworkhunting methodologyrepeatable processactionable steps - Question #42Threat Hunting Fundamentals
Which of the following is an example of a Falcon threat hunting lead?
threat hunting leadsFalcon detectionshunting triggersprocess execution - Question #43Falcon Platform Investigation
The Falcon Detections page will attempt to decode Encoded PowerShell Command line parameters when which PowerShell Command line parameter is present?
PowerShellencoded commandsFalcon Detectionscommand line parameters - Question #44Threat Hunting Methodology
Which structured analytic technique contrasts different hypotheses to determine which is the best leading (prioritized) hypothesis?
structured analytic techniquescompeting hypotheseshypothesis prioritizationanalytic methodology - Question #45Falcon Event Search
Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?
SPLFalcon Event SearchUnix epoch timetime conversion - Question #46Falcon Platform Investigation
What is the difference between a Host Search and a Host Timeline?
Host SearchHost TimelineFalcon UIinvestigation workflow - Question #47Falcon Event Data
The Process Timeline Events Details table will populate the Parent Process ID and the Parent File columns when the cloudable Event data contains which event field?
Process TimelineParentProcessIdevent fieldsprocess hierarchy - Question #48Falcon Platform Investigation
While you're reviewing Unresolved Detections in the Host Search page, you notice the User Name column contains "hostnameS". What does this User Name indicate?
Host Searchsystem userUser Name fieldevent interpretation - Question #49Falcon Platform Investigation
Which of the following is TRUE about a Hash Search?
Hash Searchprocess execution historymodule load historyFalcon investigation - Question #50Falcon Platform Configuration
With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of the following outlines...
Custom Alertsalert configurationemail templatesscheduled alerts - Question #51Threat Hunting Methodology
The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against y...
hunting hypothesispassword guessingaccount lockoutthreat analysis