CrowdStrike Certified Falcon Hunter - CCFH-202b Exam Practice Test
Which of the following would be the correct field name to find the name of an event?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
In the Powershell Hunt report, what does the "score" signify?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?
Correct Answer: D
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following Event Search queries would only find the DNS lookups to the domain: www randomdomain com?
Correct Answer: D
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
To find events that are outliers inside a network,___________is the best hunting method to use.
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).