Labour Day Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

CrowdStrike CCFH-202 CrowdStrike Certified Falcon Hunter Exam Practice Test

Demo: 9 questions
Total 60 questions

CrowdStrike Certified Falcon Hunter Questions and Answers

Question 1

The Process Timeline Events Details table will populate the Parent Process ID and the Parent File columns when the cloudable Event data contains which event field?

Options:

A.

ContextProcessld_decimal

B.

RawProcessld_decimal

C.

ParentProcessld_decimal

D.

RpcProcessld_decimal

Question 2

An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host What is this type of analysis called?

Options:

A.

Visualization of hosts

B.

Statistical analysis

C.

Temporal analysis

D.

Machine Learning

Question 3

To find events that are outliers inside a network,___________is the best hunting method to use.

Options:

A.

time-based

B.

machine learning

C.

searching

D.

stacking

Question 4

Adversaries commonly execute discovery commands such as netexe, ipconfig.exe, and whoami exe. Rather than query for each of these commands individually, you would like to use a single query with all of them. What Splunk operator is needed to complete the following query?

Options:

A.

OR

B.

IN

C.

NOT

D.

AND

Question 5

What is the difference between a Host Search and a Host Timeline?

Options:

A.

Host Search is used for detection investigation and Host Timeline is used for proactive hunting

B.

A Host Search organizes the data in useful event categories like process executions and network connections, a Host Timeline provides an uncategorized view of recorded events in chronological order

C.

You access a Host Search from a detection to show you every recorded process event related to the detection and you can only populate the Host Timeline fields manually

D.

There is no difference. You just get to them different ways

Question 6

You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc.Which command would be the appropriate choice?

Options:

A.

fields

B.

distinctcount

C.

table

D.

values

Question 7

While you're reviewing Unresolved Detections in the Host Search page, you notice the User Name column contains "hostnameS " What does this User Name indicate?

Options:

A.

The User Name is a System User

B.

The User Name is not relevant for the dashboard

C.

There is no User Name associated with the event

D.

The Falcon sensor could not determine the User Name

Question 8

Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?

Options:

A.

utc_time

B.

conv_time

C.

_time

D.

time

Question 9

In the MITRE ATT&CK Framework (version 11 - the newest version released in April 2022), which of the following pair of tactics is not in the Enterprise: Windows matrix?

Options:

A.

Persistence and Execution

B.

Impact and Collection

C.

Privilege Escalation and Initial Access

D.

Reconnaissance and Resource Development

Demo: 9 questions
Total 60 questions