CCFH-202B Exam Questions
87 real CCFH-202B exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #52
To find events that are outliers inside a network,___________is the best hunting method to use.
- Question #53
Which of the following is a way to create event searches that run automatically and recur on a schedule that you set?
- Question #54
Which of the following is a recommended technique to find unique outliers among a set of data in the Falcon Event Search?
- Question #55
Adversaries commonly execute discovery commands such as net.exe, ipconfig.exe, and whoami.exe. Rather than query for each of these commands individually, you would like to use a si...
- Question #56
You would like to search for ANY process execution that used a file stored in the Recycle Bin on a Windows host. Select the option to complete the following EAM query. aid=my-aid I...
- Question #57
Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?
- Question #58
Refer to Exhibit. What type of attack would this process tree indicate?
- Question #59
Which pre-defined reports offer information surrounding activities that typically indicate suspicious activity occurring on a system?
- Question #60
Lateral movement through a victim environment is an example of which stage of the Cyber Kill Chain?
- Question #61
When looking at a process tree, what do the nodes represent?
- Question #62
Suspicious RDP connections have been observed on a host within your environment. How do you utilize Event Search to show all connections on this specific host?
- Question #63
To best determine the root cause of an enterprise wide infection you would:
- Question #64
Which of the following process trees should raise the most suspicion that adversary activity may be present on a web server?
- Question #65
When searching for all events related to a specific process which field(s) should be selected in a query from the Event Actions drop down menu?
- Question #66
Your environment has several PowerShell scripts running that are Base64 encoded. Which of the following areas of Falcon will show you the decoded PowerShell commands?
- Question #67
Where in the Falcon console do you find hunting reports?
- Question #68
Which report would you use to find when a specific user last reset their password?
- Question #69
How would you find a list of executables running from the Recycle Bin across your environment?
- Question #70
Which document in the Support and Resources section will help you write queries by providing prebuilt examples that you could modify? One such example shows execution of common rec...
- Question #71
What document in the Support and Resources section will provide you with a breakdown of event types and related fields?
- Question #72
The MITRE ATT&CK Framework includes all of the following matrices, except:
- Question #73
Which information is returned after querying a hash on the Hash Search page?
- Question #74
When configuring a custom alert, how do you separate recipient email addresses if including more than 1 recipient?
- Question #75
Your organization's next-gen firewall has detected evidence of DNS beaconing occurring from an internal source. The firewall provides you with the beaconing host's internal (privat...
- Question #76
When reviewing a DNS request in the Event Search, you're curious which process made the request. Which Event Action would be the quickest way to show you the process?
- Question #77
What kind of IP addresses are found using an IP Search?
- Question #78
Which event_simpleName has a field that contains the command line used to create a process?
- Question #79
You have found a hash-based indicator of compromise (IOC) in an intelligence report and want to determine if the program has run in your environment. Which search would provide all...
- Question #80
While on the Statistics tab in Event Search you can click on results to perform a number of actions. If you select "Exclude from results" what happens?
- Question #81
Event Search queries in Falcon are powered by which query language?
- Question #82
What is the purpose of the rename command in this query? event_simpleName=ProcessRollup2 [search event_simpleName=ProcessRollup2 FileName=excel.exe | rename TargetProcessId_decimal...
- Question #83
Which event field contains the Falcon generated ID for a process?
- Question #84
You initiate a search with the following query: event_simpleName=UserLogon | table _time ComputerName UserName What results will display?
- Question #85
What command will eliminate duplicates from a query?
- Question #86
During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all f...
- Question #87
When looking at a detection's details, you can pivot to an Event Search. What is the purpose of this Event Search?
- Question #88
What part of the Investigate module should you use when you want to write custom queries to analyze, explore, or hunt for suspicious or malicious activity in your environment?