ExamDumpster

Free CCFH-202 sample questions

Real questions from the Crowdstrike Certified Falcon Hunter practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A threat hunter is investigating a custom-compiled variant of Mimikatz. The malicious binary was executed on a single host and immediately deleted by the adversary. No file hash is available. Which Falcon search feature is the most effective starting point to identify other hosts where this specific binary may have been executed?

Question 2Choose one

A security analyst is building a CQL query to identify potential DNS tunneling activity. The goal is to find hosts making an unusually high number of DNS requests for subdomains of a single parent domain. Which combination of CQL functions is best suited for this task?

Question 3Choose one

During an investigation, a hunter analyzes a process tree where `winword.exe` spawns `cmd.exe`, which in turn launches `powershell.exe`. In the context of Falcon event data, what are the respective process relationships of `cmd.exe`?

Question 4Choose 2

A threat hunter is developing a hypothesis that adversaries are using a specific living-off-the-land binary (LOLBAS), `certutil.exe`, to download payloads from the internet. Which of the following activities, when combined, provide the strongest evidence to validate this hypothesis? (Select TWO)

Question 5Choose one

A hunter observes a detection for PowerShell executing a command containing `-e` followed by a long, seemingly random string of characters. The Falcon UI automatically decodes this string. This behavior is most indicative of which MITRE ATT&CK technique?

Question 6Choose one

True or False: The `stats` command in CQL can only be used to count events and cannot calculate other mathematical aggregations like averages or sums.

Question 7Choose one

A pharmaceutical company is investigating a potential data exfiltration incident. The primary suspect is a disgruntled scientist who recently left the company. The security team believes the scientist may have used a cloud storage synchronization client to upload proprietary research data from their corporate laptop just before their departure. The security team has the scientist's laptop under forensic hold but first wants to use Falcon to quickly scope the activity across the environment. The known information is the name of a common cloud sync application (`megasync.exe`), the user's account name (`j.doe`), and the timeframe of the activity (the last 48 hours before the account was disabled). The goal is to create a report for management that visualizes the volume of outbound data per host associated with this user and application, to prioritize which other machines might have been compromised or used for exfiltration. Which approach in Falcon would most efficiently achieve this goal?

Question 8Choose one

A hunter needs to create a CQL query that finds all `FileWritten` events but excludes any writes to files with `.log` or `.tmp` extensions. What is the correct syntax to achieve this?

Question 9Choose one

When analyzing a Host Timeline, a threat hunter needs to understand the state of the host at a specific point in time, including running processes and network connections. Which built-in Falcon feature, accessible from the Host Management page, provides this detailed point-in-time snapshot?

Question 10Choose one

A hunter is investigating an alert where `lsass.exe` crashed on a domain controller. The hypothesis is that an attacker attempted to dump credentials. To find the process that interacted with `lsass.exe` just before the crash, what is the most precise event to search for?

10 more free samples are waiting

Create a free account to unlock the whole CCFH-202 sample bank, or get full access to all 218 practice questions in the simulator.

Create account