Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

CrowdStrike Certified Falcon Hunter

Last Update 2 hours ago Total Questions : 60

The CrowdStrike Certified Falcon Hunter content is now fully updated, with all current exam questions added 2 hours ago. Deciding to include CCFH-202b practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CCFH-202b exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CCFH-202b sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any CrowdStrike Certified Falcon Hunter practice test comfortably within the allotted time.

Question # 11

You want to use result data from an Advanced Event Search to create a custom dashboard that will display the total number of detections in a seven-day time period. Which widget will allow you to display the total number of detections as a single value digit?

A.

Gauge Widget

B.

Time Chart Widget

C.

Scatter Chart Widget

D.

Heat Map Widget

Question # 12

Your organization has identified a malicious Scheduled task that executes every 5 minutes. Which LogScale event search function can be used to quickly identify and display the unique hosts affected by the malware?

A.

stats

B.

table()

C.

groupBy()

D.

uniq

Question # 13

You receive an alert for the following process tree:

w3wp.exe > powershell.exe > cmd.exe > whoami.exe > net1.exe Which of the following describes what has occurred?

A.

Reconnaissance commands run via a webserver compromise

B.

Webserver troubleshooting user access issues by querying whoami and net1

C.

Email gateway automating routine tasks for networking configuration

D.

Email gateway validating user permissions with whoami and network status with net1

Question # 14

You are searching for all events related to a specific process. Which fields should be selected in a query?

A.

TargetProcessId and ContextProcessId

B.

ContextProcessId and timestamp

C.

timestamp and TargetProcessId

Question # 15

Which is a normal parent of cmd.exe on Windows?

A.

explorer.exe

B.

userinit.exe

C.

svchost.exe

D.

winlogon.exe

Question # 16

Your organization uses an internally developed application for operations. The application is triggering Indicators of Attack (IOA) detections for vulnerable driver usage on servers where Falcon was just installed. After reviewing the application, you determine that application behavior is expected. What will reduce risk in the environment the most?

A.

Update the vulnerable driver to a non-vulnerable recent version

B.

Create a Machine Learning Exclusion

C.

Create an IOA exclusion for this activity

D.

Create a Sensor Visibility Exclusion

Question # 17

During an investigation, you discover a Falcon host connecting from a country outside of those you normally do business with. Which built-in report would display Falcon hosts connecting from that country?

A.

Geo location activity

B.

Attack Paths

C.

Remote access graph

D.

Global connection heat map

Question # 18

You've been tasked with writing a query that would rename the RemoteAddressIP4 field to SourceIP. What would be the correct syntax using the rename() function?

A.

| rename(RemoteAddressIP=SourceIP)

B.

| rename(RemoteAddressIP4, as=SourceIP)

C.

| rename(RemoteAddressIP4 > > SourceIP)

D.

| rename(RemoteAddressIP4 := SourceIP)

Go to page: