CCFH-202B Exam Questions
87 real CCFH-202B exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #52Threat Hunting Methodology
To find events that are outliers inside a network,___________is the best hunting method to use.
outlier detectionstackinghunting methodsfrequency analysis - Question #53Falcon Platform Features
Which of the following is a way to create event searches that run automatically and recur on a schedule that you set?
scheduled searchesevent search automationrecurring queries - Question #54Falcon Event Search
Which of the following is a recommended technique to find unique outliers among a set of data in the Falcon Event Search?
stackingfrequency analysisoutlier detectionFalcon Event Search - Question #55Falcon Event Search
Adversaries commonly execute discovery commands such as net.exe, ipconfig.exe, and whoami.exe. Rather than query for each of these commands individually, you would like to use a si...
SPLOR operatorquery syntaxprocess execution hunting - Question #56Falcon Event Search
You would like to search for ANY process execution that used a file stored in the Recycle Bin on a Windows host. Select the option to complete the following EAM query. aid=my-aid I...
wildcard searchEAM queryRecycle Bin detectionFalcon Event Search - Question #57Falcon Event Search
Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?
SPL stats commandfrequency analysisoutlier identificationevent search - Question #58Threat Detection and Investigation
Refer to Exhibit. What type of attack would this process tree indicate?
process tree analysisphishing attackattack classificationdetection investigation - Question #59Falcon Platform Features
Which pre-defined reports offer information surrounding activities that typically indicate suspicious activity occurring on a system?
hunt reportspredefined reportssuspicious activity monitoring - Question #60Threat Intelligence and Kill Chain
Lateral movement through a victim environment is an example of which stage of the Cyber Kill Chain?
Cyber Kill Chainlateral movementattack stagesthreat intelligence - Question #61Process Analysis and Investigation
When looking at a process tree, what do the nodes represent?
process treeprocess executionthreat hunting - Question #62Event Search and Query Construction
Suspicious RDP connections have been observed on a host within your environment. How do you utilize Event Search to show all connections on this specific host?
Event SearchRDPLogonTypequery syntax - Question #63Incident Investigation and Root Cause Analysis
To best determine the root cause of an enterprise wide infection you would:
root cause analysishash analysisprocess execution timelineincident response - Question #64Process Analysis and Investigation
Which of the following process trees should raise the most suspicion that adversary activity may be present on a web server?
process tree analysisweb serveranomalous child processesadversary activity - Question #65Event Search and Query Construction
When searching for all events related to a specific process which field(s) should be selected in a query from the Event Actions drop down menu?
Event ActionsTargetProcessIdContextProcessIdprocess search - Question #66Malware and Script Analysis
Your environment has several PowerShell scripts running that are Base64 encoded. Which of the following areas of Falcon will show you the decoded PowerShell commands?
PowerShellBase64 encodingcommand linedetection details - Question #67Falcon Platform Navigation and Features
Where in the Falcon console do you find hunting reports?
Falcon console navigationhunting reportsInvestigate module - Question #68User Activity Investigation
Which report would you use to find when a specific user last reset their password?
User Timelinepassword resetuser activity reporting - Question #69Threat Hunting Reports
How would you find a list of executables running from the Recycle Bin across your environment?
hunt reportsRecycle Binexecutable hunting - Question #70Falcon Platform Navigation and Features
Which document in the Support and Resources section will help you write queries by providing prebuilt examples that you could modify? One such example shows execution of common rec...
Hunting and Investigation guidequery examplesSupport resources - Question #71Falcon Platform Navigation and Features
What document in the Support and Resources section will provide you with a breakdown of event types and related fields?
Events Data Dictionaryevent typesfield referencedocumentation - Question #72Threat Intelligence Frameworks
The MITRE ATT&CK Framework includes all of the following matrices, except:
MITRE ATT&CKframework matricesthreat intelligence - Question #73IOC Investigation and Hash Analysis
Which information is returned after querying a hash on the Hash Search page?
Hash SearchFirst Seen DateIOC analysis - Question #74Falcon Platform Configuration
When configuring a custom alert, how do you separate recipient email addresses if including more than 1 recipient?
custom alertsemail configurationFalcon console settings - Question #75Network-Based Threat Hunting
Your organization's next-gen firewall has detected evidence of DNS beaconing occurring from an internal source. The firewall provides you with the beaconing host's internal (privat...
IP SearchDNS beaconingSource IPhost identification - Question #76Event Search and Query Construction
When reviewing a DNS request in the Event Search, you're curious which process made the request. Which Event Action would be the quickest way to show you the process?
DNS requestEvent Searchresponsible processEvent Actions - Question #77Falcon Platform Navigation and Features
What kind of IP addresses are found using an IP Search?
IP SearchSource IPDestination IPExternal IP - Question #78Event Search and Query Construction
Which event_simpleName has a field that contains the command line used to create a process?
ProcessRollup2event_simpleNamecommand lineprocess creation - Question #79IOC Investigation and Hash Analysis
You have found a hash-based indicator of compromise (IOC) in an intelligence report and want to determine if the program has run in your environment. Which search would provide all...
IOC Searchhash searchprocess executionindicator of compromise - Question #80Event Search and Query Construction
While on the Statistics tab in Event Search you can click on results to perform a number of actions. If you select "Exclude from results" what happens?
Event SearchStatistics tabquery filteringsearch refinement - Question #81Falcon Event Search and Investigation
Event Search queries in Falcon are powered by which query language?
Event SearchSplunk Query LanguageSPLFalcon platform - Question #82Event Search Query Construction
What is the purpose of the rename command in this query? event_simpleName=ProcessRollup2 [search event_simpleName=ProcessRollup2 FileName=excel.exe | rename TargetProcessId_decimal...
SPL rename commandsub-searchparent-child processesprocess lineage - Question #83Falcon Event Schema and Fields
Which event field contains the Falcon generated ID for a process?
TargetProcessId_decimalFalcon event fieldsprocess identificationProcessRollup2 - Question #84Event Search Query Construction
You initiate a search with the following query: event_simpleName=UserLogon | table _time ComputerName UserName What results will display?
table command_time fieldhuman-readable timeUserLogon event - Question #85Event Search Query Construction
What command will eliminate duplicates from a query?
dedup commandSPL commandsduplicate removaldata filtering - Question #86Threat Investigation and Hunting
During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all f...
file write eventsContextProcessId_decimalprocess investigationmalware hunting - Question #87Falcon Detection Investigation
When looking at a detection's details, you can pivot to an Event Search. What is the purpose of this Event Search?
detection pivotEvent Searchinvestigation workflowdetection context - Question #88Falcon Investigation Modules
What part of the Investigate module should you use when you want to write custom queries to analyze, explore, or hunt for suspicious or malicious activity in your environment?
Event SearchInvestigate modulethreat huntingcustom queries