Brilliant CCFH-202 Exam Dumps Get CCFH-202 Dumps PDF
CCFH-202 Dumps PDF - CCFH-202 Real Exam Questions Answers
NEW QUESTION # 34
An analyst has sorted all recent detections in the Falcon platform to identify the oldest in an effort to determine the possible first victim host What is this type of analysis called?
- A. Visualization of hosts
- B. Statistical analysis
- C. Machine Learning
- D. Temporal analysis
Answer: D
Explanation:
Temporal analysis is a type of analysis that focuses on the timing and sequence of events in order to identify patterns, trends, or anomalies. By sorting all recent detections in the Falcon platform to identify the oldest, an analyst can perform temporal analysis to determine the possible first victim host and trace back the origin of an attack.
NEW QUESTION # 35
What kind of activity does a User Search help you investigate?
- A. A history of Falcon Ul logon activity
- B. A list of process activity executed by the specified user account
- C. A list of DNS queries by the specified user account
- D. A count of failed user logon activity
Answer: B
Explanation:
User Search is an Investigate tool that helps you investigate a list of process activity executed by the specified user account. It shows information such as process name, command line, parent process name, parent command line, etc. for each process that was executed by the user account on any host in your environment. It does not show a history of Falcon UI logon activity, a count of failed user logon activity, or a list of DNS queries by the specified user account.
NEW QUESTION # 36
In the Powershell Hunt report, what does the "score" signify?
- A. Number of hosts that ran the PowerShell script
- B. A cumulative score of the various potential command line switches
- C. How recently the PowerShell script executed
- D. Maliciousness score determined by NGAV
Answer: B
Explanation:
In the Powershell Hunt report, the score signifies a cumulative score of the various potential command line switches that were used in the PowerShell script execution. The score is based on a weighted system that assigns different values to different switches based on their potential maliciousness or usefulness for threat hunting. For example, -EncodedCommand has a higher value than -NoProfile. The score does not signify the number of hosts that ran the PowerShell script, how recently the PowerShell script executed, or the maliciousness score determined by NGAV.
NEW QUESTION # 37
How do you rename fields while using transforming commands such as table, chart, and stats?
- A. By using the "renamed" keyword after the field name eg "stats count renamed totalcount by ComputerName"
- B. By specifying the desired name after the field name eg "stats count totalcount by ComputerName"
- C. You cannot rename fields as it would affect sub-queries and statistical analysis
- D. By renaming the fields with the "rename" command after the transforming command e.g. "stats count by ComputerName | rename count AS total_count"
Answer: D
Explanation:
The rename command is used to rename fields while using transforming commands such as table, chart, and stats. It can be used after the transforming command and specify the old and new field names with the AS keyword. You can rename fields as it would not affect sub-queries and statistical analysis, as long as you use the correct field names in your queries. The renamed keyword and the desired name after the field name are not valid ways to rename fields.
NEW QUESTION # 38
Which structured analytic technique contrasts different hypotheses to determine which is the best leading (prioritized) hypothesis?
- A. Key assumptions check
- B. Model hunting framework
- C. Competitive analysis
- D. Analysis of competing hypotheses
Answer: D
Explanation:
Analysis of competing hypotheses is a structured analytic technique that contrasts different hypotheses to determine which is the best leading (prioritized) hypothesis. It involves listing all the possible hypotheses, identifying the evidence and assumptions for each hypothesis, evaluating the consistency and reliability of the evidence and assumptions, and rating the likelihood of each hypothesis based on the evidence and assumptions.
NEW QUESTION # 39
Refer to Exhibit.
Falcon detected the above file attempting to execute. At initial glance; what indicators can we use to provide an initial analysis of the file?
- A. File path, hard disk volume number, and IOC Management action
- B. File name, path, Local and Global prevalence within the environment
- C. Local prevalence, IOC Management action, and Event Search
- D. VirusTotal, Hybrid Analysis, and Google pivot indicator lights enabled
Answer: B
Explanation:
The file name, path, Local and Global prevalence are indicators that can provide an initial analysis of the file without relying on external sources or tools. The file name can indicate the purpose or origin of the file, such as if it is a legitimate application or a malicious payload. The file path can indicate where the file was located or executed from, such as if it was in a temporary or system directory. The Local and Global prevalence can indicate how common or rare the file is within the environment or across all Falcon customers, which can help assess the risk or impact of the file.
NEW QUESTION # 40
Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
- A. MITRE-Based Falcon Detections Framework
- B. Hunting and Investigation
- C. Customizable Dashboards
- D. Events Data Dictionary
Answer: B
Explanation:
The Hunting and Investigation guide is the Falcon documentation guide that you should reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts. The Hunting and Investigation guide provides sample hunting queries, select walkthroughs, and best practices for hunting with Falcon. It covers various topics such as process execution, network connections, registry activity, scheduled tasks, and more.
NEW QUESTION # 41
Which of the following best describes the purpose of the Mac Sensor report?
- A. The Mac Sensor report displays a listing of all Mac hosts with a Falcon sensor installed
- B. The Mac Sensor report displays a listing of all Mac hosts without a Falcon sensor installed
- C. The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads
- D. The Mac Sensor report provides a detection focused view of known malicious activities occurring on Mac hosts, including machine-learning and indicator-based detections
Answer: C
Explanation:
This is the correct answer for the same reason as above. The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads. It does not display a listing of all Mac hosts with or without a Falcon sensor installed, nor does it provide a detection focused view of known malicious activities occurring on Mac hosts.
NEW QUESTION # 42
Which field in a DNS Request event points to the responsible process?
- A. ContextProcessld_readable
- B. TargetProcessld_decimal
- C. ParentProcessId_decimal
- D. ContextProcessld_decimal
Answer: A
Explanation:
The ContextProcessld_readable field in a DNS Request event points to the responsible process. The ContextProcessld_readable field is the readable representation of the process identifier for the process that initiated the DNS request. It can be used to identify which process was communicating with a specific domain or IP address. The TargetProcessld_decimal, ContextProcessld_decimal, and ParentProcessId_decimal fields do not point to the responsible process.
NEW QUESTION # 43
Which pre-defined reports offer information surrounding activities that typically indicate suspicious activity occurring on a system?
- A. Timeline reports
- B. Scheduled searches
- C. Sensor reports
- D. Hunt reports
Answer: D
Explanation:
Hunt reports are pre-defined reports that offer information surrounding activities that typically indicate suspicious activity occurring on a system. They are based on common threat hunting use cases and queries, and they provide visualizations and summaries of the results. Hunt reports can help threat hunters quickly identify and investigate potential threats in their environment.
NEW QUESTION # 44
You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each domain. Which tool should you use in Falcon?
- A. Allowed Domain Summary Report
- B. Create a custom alert for each domain
- C. Bulk Domain Search
- D. IP Addresses Search
Answer: C
Explanation:
Bulk Domain Search is the tool that you should use in Falcon to review a list of domains recently banned by your organization's acceptable use policy and look for the number of hosts that have visited each domain. Bulk Domain Search is an Investigate tool that allows you to search for multiple domains at once and view their network connection events across all hosts in your environment. It shows information such as domain name, number of hosts visited, number of detections generated, etc. for each domain. Create a custom alert for each domain, Allowed Domain Summary Report, and IP Addresses Search are not tools that you should use for this purpose.
NEW QUESTION # 45
Which field should you reference in order to find the system time of a *FileWritten event?
- A. timestamp
- B. FileTimeStamp_decimal
- C. ProcessStartTime_decimal
- D. ContextTimeStamp_decimal
Answer: D
Explanation:
ContextTimeStamp_decimal is the field that shows the system time of the event that triggered the sensor to send data to the cloud. In this case, it would be the time when the file was written. FileTimeStamp_decimal is the field that shows the last modified time of the file, which may not be the same as the time when the file was written. ProcessStartTime_decimal is the field that shows the start time of the process that performed the file write operation, which may not be the same as the time when the file was written. Timestamp is the field that shows the time when the sensor data was received by the cloud, which may not be the same as the time when the file was written.
NEW QUESTION # 46
What Investigate tool would you use to allow an analyst to view all events for a specific host?
- A. Host Search
- B. Host Timeline
- C. Process Timeline
- D. Bulk Timeline
Answer: B
Explanation:
The Host Timeline is the Investigate tool that you would use to allow an analyst to view all events for a specific host. The Host Timeline shows a graphical representation of all events that occurred on a host within a specified time range. It allows an analyst to zoom in and out, filter by event type or name, and drill down into event details. The Bulk Timeline, the Host Search, and the Process Timeline are not Investigate tools that you would use to view all events for a specific host.
NEW QUESTION # 47
Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes?
- A. Hunting and Investigation
- B. Real Time Response and Network Containment
- C. Incident and Detection Monitoring
- D. Events Data Dictionary
Answer: A
Explanation:
The Hunting and Investigation document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes. As explained above, the Hunting and Investigation document is a guide that provides sample hunting queries, select walkthroughs, and best practices for hunting with Falcon. The other documents do not provide the same information.
NEW QUESTION # 48
Which of the following is an example of a Falcon threat hunting lead?
- A. Security appliance logs showing potentially bad traffic to an unknown external IP address
- B. An external report describing a unique 5 character file extension for ransomware encrypted files
- C. A help desk ticket for a user clicking on a link in an email causing their machine to become unresponsive and have high CPU usage
- D. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories
Answer: D
Explanation:
A Falcon threat hunting lead is a piece of information that can be used to initiate or guide a threat hunting activity within the Falcon platform. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories is an example of a Falcon threat hunting lead, as it can indicate potential malicious activity that can be further investigated using Falcon data and features. Security appliance logs, help desk tickets, and external reports are not examples of Falcon threat hunting leads, as they are not directly related to the Falcon platform or data.
NEW QUESTION # 49
Which of the following is a suspicious process behavior?
- A. PowerShell launching a PowerShell script
- B. An Internet browser (eg, Internet Explorer) performing multiple DNS requests
- C. PowerShell running an execution policy of RemoteSigned
- D. Non-network processes (eg, notepad exe) making an outbound network connection
Answer: D
Explanation:
Non-network processes are processes that are not expected to communicate over the network, such as notepad.exe. If they make an outbound network connection, it could indicate that they are compromised or maliciously used by an adversary. PowerShell running an execution policy of RemoteSigned is a default setting that allows local scripts to run without digital signatures. An Internet browser performing multiple DNS requests is a normal behavior for web browsing. PowerShell launching a PowerShell script is also a common behavior for legitimate tasks.
NEW QUESTION # 50
SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time Which eval function is correct^
- A. now
- B. strftime
- C. relative time
- D. typeof
Answer: B
Explanation:
The strftime eval function is used to convert Unix times (Epoch) into UTC readable time. It takes two arguments: a Unix time field and a format string that specifies how to display the time. The now, typeof, and relative_time eval functions are not used to convert Unix times into UTC readable time.
NEW QUESTION # 51
What information is provided when using IP Search to look up an IP address?
- A. Internal IPs only
- B. Both internal and external IPs
- C. External IPs only
- D. Suspicious IP addresses
Answer: C
Explanation:
IP Search is an Investigate tool that allows you to look up information about external IPs only. It shows information such as geolocation, network connection events, detection history, etc. for each external IP address that has communicated with your hosts. It does not show information about internal IPs, suspicious IPs, or both internal and external IPs.
NEW QUESTION # 52
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
- A. Command & control
- B. Exploitation
- C. Weaponization
- D. Installation
Answer: C
Explanation:
Weaponization is the stage of the Cyber Kill Chain where the actor does not interact with the victim endpoint(s). Weaponization is where the actor prepares or packages the exploit or payload that will be used to compromise the target. This stage does not involve any communication or interaction with the victim endpoint(s), as it is done by the actor before delivering the weaponized content. Exploitation, Command & Control, and Installation are all stages where the actor interacts with the victim endpoint(s), either by executing code, establishing communication, or installing malware.
NEW QUESTION # 53
SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time Which eval function is correct^
- A. now
- B. strftime
- C. relative time
- D. typeof
Answer: B
Explanation:
The strftime eval function is used to convert Unix times (Epoch) into UTC readable time. It takes two arguments: a Unix time field and a format string that specifies how to display the time. The now, typeof, and relative_time eval functions are not used to convert Unix times into UTC readable time.
NEW QUESTION # 54
What information is provided from the MITRE ATT&CK framework in a detection's Execution Details?
- A. Grouping Tag
- B. Technique ID
- C. Triggering Indicator
- D. Command Line
Answer: B
Explanation:
Technique ID is the information that is provided from the MITRE ATT&CK framework in a detection's Execution Details. Technique ID is a unique identifier for each technique in the MITRE ATT&CK framework, such as T1059 for Command and Scripting Interpreter or T1566 for Phishing. Technique ID helps to map a detection to a specific adversary behavior and tactic. Grouping Tag, Command Line, and Triggering Indicator are not information that is provided from the MITRE ATT&CK framework in a detection's Execution Details.
NEW QUESTION # 55
......
CrowdStrike CCFH-202 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
Valid CCFH-202 Test Answers & CrowdStrike CCFH-202 Exam PDF: https://www.exam4free.com/CCFH-202-valid-dumps.html
Realistic CCFH-202 Exam Dumps with Accurate & Updated Questions: https://drive.google.com/open?id=1eKCpc44Lm66pNNQI-UKivl-sT-Am_B7G
