Skip to content

CCFH-202 Crowdstrike Certified Falcon Hunter Practice Questions

Prepare for CCFH-202 with more than an answer.

218 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$300 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 7
  1. MITRE ATT&CK Frameworks15%
  2. Detection Analysis15%
  3. Search and Investigation Tools15%
  4. Event Search20%
  5. Reports and References10%
  6. Hunting Analytics15%
  7. Hunting Methodology10%
  1. 1

    Which three of the following are considered distinct phases of the Cyber Kill Chain model? (Select THREE)

    Show answer details

    Correct answer: B, C, E

    Exploitation is the phase where the adversary takes advantage of a vulnerability to execute code on a victim's system.

    Command and Control is the phase where the malware establishes a communication channel back to the attacker to receive instructions.

    Actions on Objectives is the final phase where the adversary accomplishes their ultimate goal, such as data exfiltration or destruction.

  2. 2

    A hunter needs to find evidence of Timestomping, a technique used by adversaries to modify file timestamps to evade detection. Which Falcon event contains the most relevant information for this type of investigation?

    Show answer details

    Correct answer: C

    The SetFileTimestamp event is specifically generated when an action modifies a file's timestamps (creation, modification, access). This event is the most direct and high-fidelity source for detecting Timestomping activity, as it captures the exact moment the modification occurred and which process was responsible.

  3. 3

    When reviewing the Process Timeline for a detection, a hunter wants to understand the full context of the execution, including processes that were launched both before and after the alert triggered. Which control in the Process Timeline view allows the hunter to expand the timeframe of displayed events?

    Show answer details

    Correct answer: C

    The Process Timeline initially focuses on the events directly related to the detection. The 'Load Surrounding Events' button is specifically designed to broaden this view, pulling in events that occurred on the same host shortly before and after the detection. This provides crucial context for understanding the full attack sequence.

  4. 4

    A hunter needs to distinguish between normal administrative RDP activity and potential adversary lateral movement. Which of the following is the strongest indicator of malicious RDP usage?

    Show answer details

    Correct answer: C

    While administrators frequently use RDP to connect to servers (workstation-to-server), it is highly unusual for them to RDP from one workstation to another (workstation-to-workstation). This pattern is a classic indicator of adversary lateral movement, where an attacker who has compromised one machine uses it as a pivot point to access another.

  5. 5

    A threat analyst is reviewing the built-in Falcon reports to gain insight into suspicious file authentications across the enterprise. Which report is specifically designed to provide this information?

    Show answer details

    Correct answer: B

    Within the built-in Hunt Reports, the 'Suspicious File Authentications' report is specifically designed to highlight executables that have invalid or untrusted digital signatures. This is a common characteristic of malware or attacker tools, making this report a valuable starting point for hunts.

  6. 6

    A threat hunter is investigating a custom-compiled variant of Mimikatz. The malicious binary was executed on a single host and immediately deleted by the adversary. No file hash is available. Which Falcon search feature is the most effective starting point to identify other hosts where this specific binary may have been executed?

    Show answer details

    Correct answer: D

    Even if a file is deleted from the disk, CrowdStrike Falcon captures the hash of any process at the time of execution and records it within the ProcessRollup2 event. A threat hunter can extract this SHA256 hash and use the global Hash Search feature to find every other instance where that exact binary was executed across the entire environment, regardless of its filename or if it was subsequently deleted.

  7. 7

    A security analyst is building a CQL query to identify potential DNS tunneling activity. The goal is to find hosts making an unusually high number of DNS requests for subdomains of a single parent domain. Which combination of CQL functions is best suited for this task?

    Show answer details

    Correct answer: C

    This query correctly identifies DNS tunneling by first filtering for DNS request events. It then uses the rex command with a regular expression to extract the root domain (e.g., 'example.com' from 'a.b.c.example.com'). Finally, it uses stats to calculate the distinct count (dc) of unique full DomainName values, grouping them by the agent ID (aid) and the extracted root_domain. A high subdomain_count for a single root_domain on a specific host is a strong indicator of DNS tunneling.

  8. 8

    During an investigation, a hunter analyzes a process tree where winword.exe spawns cmd.exe, which in turn launches powershell.exe. In the context of Falcon event data, what are the respective process relationships of cmd.exe?

    Show answer details

    Correct answer: B

    In the Falcon event model, the 'Parent Process' is the process that created the event's target. The 'Target Process' is the process on which the action occurred. In the event where cmd.exe launches powershell.exe, cmd.exe is the Parent Process and powershell.exe is the Target Process. In the preceding event where winword.exe launched cmd.exe, winword.exe was the Parent Process.

  9. 9

    A threat hunter is developing a hypothesis that adversaries are using a specific living-off-the-land binary (LOLBAS), certutil.exe, to download payloads from the internet. Which of the following activities, when combined, provide the strongest evidence to validate this hypothesis? (Select TWO)

    Show answer details

    Correct answer: A, C

    The certutil.exe binary is not expected to make network connections during its normal certificate management functions. An outbound network connection is highly anomalous and directly supports the hypothesis of it being used to download files.

    These specific command-line arguments are used with certutil.exe to fetch a file from a URL and save it to the local disk. Their presence is a key indicator that the tool is being used for file download purposes, which is a common TTP for adversaries.

  10. 10

    A hunter observes a detection for PowerShell executing a command containing -e followed by a long, seemingly random string of characters. The Falcon UI automatically decodes this string. This behavior is most indicative of which MITRE ATT&CK technique?

    Show answer details

    Correct answer: B

    The -e or -encodedcommand parameter in PowerShell accepts a base64-encoded string. Adversaries use this to hide their commands from simple keyword-based detection and logging. This is a classic example of T1027: Obfuscated Files or Information, specifically sub-technique T1027.010 Command and Scripting Obfuscation.

Create an account to continue.