Dumps Moneyack Guarantee - CCFH-202 Dumps UpTo 50% Off [Q34-Q50]

Share

Dumps Moneyack Guarantee - CCFH-202 Dumps UpTo 50% Off

Updated Nov-2023 Pass CCFH-202 Exam - Real Practice Test Questions

NEW QUESTION # 34
The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against your organization. Select the best hunting hypothesis from the following:

  • A. Users are locking their accounts out because they recently changed their passwords
  • B. A zero-day vulnerability is being exploited on a Microsoft Exchange server
  • C. A password guessing attack is being executed against remote access mechanisms such as VPN
  • D. A publicly available web application has been hacked and is causing the lockouts

Answer: C

Explanation:
A hunting hypothesis is a statement that describes a possible malicious activity that can be tested with data and analysis. A good hunting hypothesis should be specific, testable, and relevant to the problem or goal. In this case, the best hunting hypothesis from the following is that a password guessing attack is being executed against remote access mechanisms such as VPN, as it explains the possible cause and method of the user account lockouts in a specific and testable way. A zero-day vulnerability on a Microsoft Exchange server is too vague and does not explain how it relates to the lockouts. A hacked web application is also too vague and does not specify how it causes the lockouts. Users locking their accounts out because they recently changed their passwords is not a malicious activity and does not account for the increase in calls.


NEW QUESTION # 35
In the MITRE ATT&CK Framework (version 11 - the newest version released in April 2022), which of the following pair of tactics is not in the Enterprise: Windows matrix?

  • A. Impact and Collection
  • B. Persistence and Execution
  • C. Privilege Escalation and Initial Access
  • D. Reconnaissance and Resource Development

Answer: D

Explanation:
Reconnaissance and Resource Development are two tactics that are not in the Enterprise: Windows matrix of the MITRE ATT&CK Framework (version 11). These two tactics are part of the PRE-ATT&CK matrix, which covers the actions that adversaries take before compromising a target. The Enterprise: Windows matrix covers the actions that adversaries take after gaining initial access to a Windows system. Persistence, Execution, Impact, Collection, Privilege Escalation, and Initial Access are all tactics that are in the Enterprise: Windows matrix.


NEW QUESTION # 36
Which field in a DNS Request event points to the responsible process?

  • A. ParentProcessId_decimal
  • B. ContextProcessld_decimal
  • C. TargetProcessld_decimal
  • D. ContextProcessld_readable

Answer: D

Explanation:
The ContextProcessld_readable field in a DNS Request event points to the responsible process. The ContextProcessld_readable field is the readable representation of the process identifier for the process that initiated the DNS request. It can be used to identify which process was communicating with a specific domain or IP address. The TargetProcessld_decimal, ContextProcessld_decimal, and ParentProcessId_decimal fields do not point to the responsible process.


NEW QUESTION # 37
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?

  • A. Director of National Intelligence Cyber Threat Framework
  • B. MITRE ATT&CK
  • C. NIST 800-171 Cyber Threat Framework
  • D. Lockheed Martin Cyber Kill Chain

Answer: B

Explanation:
MITRE ATT&CK is a threat framework that allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies. It is a knowledge base of adversary behaviors and tactics that covers various platforms, domains, and scenarios. It provides a common language and structure for threat hunters to understand and analyze threats, as well as to share findings and recommendations.


NEW QUESTION # 38
What Investigate tool would you use to allow an analyst to view all events for a specific host?

  • A. Bulk Timeline
  • B. Host Search
  • C. Process Timeline
  • D. Host Timeline

Answer: D

Explanation:
The Host Timeline is the Investigate tool that you would use to allow an analyst to view all events for a specific host. The Host Timeline shows a graphical representation of all events that occurred on a host within a specified time range. It allows an analyst to zoom in and out, filter by event type or name, and drill down into event details. The Bulk Timeline, the Host Search, and the Process Timeline are not Investigate tools that you would use to view all events for a specific host.


NEW QUESTION # 39
Which of the following is TRUE about a Hash Search?

  • A. The Hash Search is available on Linux
  • B. The Hash Search provides Process Execution History
  • C. Module Load History is not presented in a Hash Search
  • D. Wildcard searches are not permitted with the Hash Search

Answer: B

Explanation:
The Hash Search is an Investigate tool that allows you to search for a file hash and view its process execution history across all hosts in your environment. It shows information such as process name, command line, parent process name, parent command line, etc. for each execution of the file hash. Wildcard searches are permitted with the Hash Search, as long as they are at least four characters long. The Hash Search is available on Linux, as well as Windows and Mac OS X. Module Load History is presented in a Hash Search, along with other information such as File Write History and Detection History.


NEW QUESTION # 40
Which of the following best describes the purpose of the Mac Sensor report?

  • A. The Mac Sensor report displays a listing of all Mac hosts with a Falcon sensor installed
  • B. The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads
  • C. The Mac Sensor report displays a listing of all Mac hosts without a Falcon sensor installed
  • D. The Mac Sensor report provides a detection focused view of known malicious activities occurring on Mac hosts, including machine-learning and indicator-based detections

Answer: B

Explanation:
This is the correct answer for the same reason as above. The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads. It does not display a listing of all Mac hosts with or without a Falcon sensor installed, nor does it provide a detection focused view of known malicious activities occurring on Mac hosts.


NEW QUESTION # 41
Which of the following does the Hunting and Investigation Guide contain?

  • A. Example Event Search queries useful for threat hunting
  • B. A list of all event types specifically used for hunting and their syntax
  • C. A list of all event types and their syntax
  • D. Example Event Search queries useful for Falcon platform configuration

Answer: A

Explanation:
The Hunting and Investigation guide contains example Event Search queries useful for threat hunting. These queries are based on common threat hunting use cases and scenarios, such as finding suspicious processes, network connections, registry activity, etc. The guide also explains how to customize and modify the queries to suit different needs and environments. The guide does not contain a list of all event types and their syntax, as that information is provided in the Events Data Dictionary. The guide also does not contain example Event Search queries useful for Falcon platform configuration, as that is not the focus of the guide.


NEW QUESTION # 42
You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?

  • A. values
  • B. distinct count
  • C. fields
  • D. table

Answer: D

Explanation:
The table command is used to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. It takes one or more field names as arguments and displays them in a tabular format. The fields command is used to keep or remove fields from search results, not to display them in a list. The distinct_count command is used to count the number of distinct values of a field, not to display them in a list. The values command is used to display a list of unique values of a field within each group, not to display all event occurrences.


NEW QUESTION # 43
Refer to Exhibit.

Falcon detected the above file attempting to execute. At initial glance; what indicators can we use to provide an initial analysis of the file?

  • A. Local prevalence, IOC Management action, and Event Search
  • B. VirusTotal, Hybrid Analysis, and Google pivot indicator lights enabled
  • C. File name, path, Local and Global prevalence within the environment
  • D. File path, hard disk volume number, and IOC Management action

Answer: C

Explanation:
The file name, path, Local and Global prevalence are indicators that can provide an initial analysis of the file without relying on external sources or tools. The file name can indicate the purpose or origin of the file, such as if it is a legitimate application or a malicious payload. The file path can indicate where the file was located or executed from, such as if it was in a temporary or system directory. The Local and Global prevalence can indicate how common or rare the file is within the environment or across all Falcon customers, which can help assess the risk or impact of the file.


NEW QUESTION # 44
A benefit of using a threat hunting framework is that it:

  • A. Provides actionable, repeatable steps to conduct threat hunting
  • B. Automatically generates incident reports
  • C. Provides high fidelity threat actor attribution
  • D. Eliminates false positives

Answer: A

Explanation:
A threat hunting framework is a methodology that guides threat hunters in planning, executing, and improving their threat hunting activities. A benefit of using a threat hunting framework is that it provides actionable, repeatable steps to conduct threat hunting in a consistent and efficient manner. A threat hunting framework does not automatically generate incident reports, eliminate false positives, or provide high fidelity threat actor attribution, as these are dependent on other factors such as data sources, tools, and analysis skills.


NEW QUESTION # 45
You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?

  • A. Streaming API Event Dictionary
  • B. Events Data Dictionary
  • C. Hunting and Investigation
  • D. Event stream APIs

Answer: B

Explanation:
The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because it provides a reference of information about the events found in the Investigate > Event Search page of the Falcon Console. The Events Data Dictionary describes each event type, field name, data type, description, and example value that can be used to query and analyze event data. The Streaming API Event Dictionary, Hunting and Investigation, and Event stream APIs are not documentation that provide details about key data fields and sensor events.


NEW QUESTION # 46
What topics are presented in the Hunting and Investigation Guide?

  • A. Detailed tutorial on writing advanced queries such as sub-searches and joins
  • B. Recommended platform configurations and prevention settings to ensure detections are generated for hunting leads
  • C. Detailed summary of event names, descriptions, and some key data fields for hunting and investigation
  • D. Sample hunting queries, select walkthroughs and best practices for hunting with Falcon

Answer: D

Explanation:
This is the correct answer for the same reason as above. The Hunting and Investigation guide provides sample hunting queries, select walkthroughs, and best practices for hunting with Falcon. It does not provide a detailed tutorial on writing advanced queries, a detailed summary of event names and descriptions, or recommended platform configurations and prevention settings.


NEW QUESTION # 47
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, expand and refer to the _______dashboard panel.

  • A. Command Line and Admin Tools
  • B. Processes and Services
  • C. Suspicious File Activity
  • D. Registry, Tasks, and Firewall

Answer: C

Explanation:
To view Files Written to Removable Media within a specified timeframe on a host within the Host Search page, you need to expand and refer to the Suspicious File Activity dashboard panel. The Suspicious File Activity dashboard panel shows information such as files written to removable media, files written to system directories by non-system processes, files written to startup folders, etc. The other dashboard panels do not show files written to removable media.


NEW QUESTION # 48
Which field should you reference in order to find the system time of a *FileWritten event?

  • A. ContextTimeStamp_decimal
  • B. ProcessStartTime_decimal
  • C. FileTimeStamp_decimal
  • D. timestamp

Answer: A

Explanation:
ContextTimeStamp_decimal is the field that shows the system time of the event that triggered the sensor to send data to the cloud. In this case, it would be the time when the file was written. FileTimeStamp_decimal is the field that shows the last modified time of the file, which may not be the same as the time when the file was written. ProcessStartTime_decimal is the field that shows the start time of the process that performed the file write operation, which may not be the same as the time when the file was written. Timestamp is the field that shows the time when the sensor data was received by the cloud, which may not be the same as the time when the file was written.


NEW QUESTION # 49
Which of the following is an example of actor actions during the RECONNAISSANCE phase of the Cyber Kill Chain?

  • A. Emailing the intended victim with a malware attachment
  • B. Discovering internet-facing servers
  • C. Loading a malicious payload into a common DLL
  • D. Installing a backdoor on the victim endpoint

Answer: B

Explanation:
Discovering internet-facing servers is an example of actor actions during the RECONNAISSANCE phase of the Cyber Kill Chain. The RECONNAISSANCE phase is where the adversary researches and identifies targets, vulnerabilities, and attack vectors. Discovering internet-facing servers is a way for the adversary to find potential entry points or weaknesses in the target network.


NEW QUESTION # 50
......

Download Free CrowdStrike CCFH-202 Real Exam Questions: https://www.dumpsreview.com/CCFH-202-exam-dumps-review.html

Pass Your Exam With 100% Verified CCFH-202 Exam Questions: https://drive.google.com/open?id=1JGRYdBY2B9QNDF5JRKnXtONKByeDSltb