CCFH-202 Sample Questions

CCFH-202 Sample Questions & Answers

Running searches in the CrowdStrike Query Language carries the top weight, alongside hunting methodology and outlier analysis, pivoting between host and process timelines, applying MITRE's ATT&CK framework with the Cyber Kill Chain, and hunt reports.

Launch the full CCFH-202 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Event Search · Build a query and perform a search using CQL

    True or False: The stats command in CQL can only be used to count events and cannot calculate other mathematical aggregations like averages or sums.

    Show answer & explanation

    Correct answer: B

    The stats command is a powerful aggregation tool in CQL. In addition to count, it supports various other functions, including avg() for average, sum() for sum, min() for minimum, max() for maximum, dc() for distinct count, and values() to list distinct values.

  2. Question 2Advanced

    Event Search · Create a custom dashboard to display Advanced Event Search results

    A pharmaceutical company is investigating a potential data exfiltration incident. The primary suspect is a disgruntled scientist who recently left the company. The security team believes the scientist may have used a cloud storage synchronization client to upload proprietary research data from their corporate laptop just before their departure.

    The security team has the scientist's laptop under forensic hold but first wants to use Falcon to quickly scope the activity across the environment. The known information is the name of a common cloud sync application (megasync.exe), the user's account name (j.doe), and the timeframe of the activity (the last 48 hours before the account was disabled).

    The goal is to create a report for management that visualizes the volume of outbound data per host associated with this user and application, to prioritize which other machines might have been compromised or used for exfiltration.

    Which approach in Falcon would most efficiently achieve this goal?

    Show answer & explanation

    Correct answer: D

    This is the most direct and efficient method. The CQL query precisely targets the exfiltration activity by filtering for outbound network events (NetworkSend) from the specific application and user. Using stats sum(bytes_sent) by ComputerName aggregates the total data sent from each host, directly answering the core investigative question. Saving this to a custom dashboard provides a clear visualization (like a bar chart) that is perfect for management reporting and prioritizing the investigation on the hosts with the highest exfiltration volumes.

  3. Question 3Intermediate

    Event Search · Filter event data and analyze results

    A hunter needs to create a CQL query that finds all FileWritten events but excludes any writes to files with .log or .tmp extensions. What is the correct syntax to achieve this?

    Show answer & explanation

    Correct answer: D

    This query correctly uses the search command with the NOT operator to exclude results. The IN operator allows for checking against a list of values. By combining NOT and IN, the query efficiently filters out any FileWritten events where the FileName ends in either .log or .tmp. The wildcards * are also correctly used to match any filename.

  4. Question 4Intermediate

    Detection Analysis · Analyze information displayed in the Host Timeline to understand host states and events

    When analyzing a Host Timeline, a threat hunter needs to understand the state of the host at a specific point in time, including running processes and network connections. Which built-in Falcon feature, accessible from the Host Management page, provides this detailed point-in-time snapshot?

    Show answer & explanation

    Correct answer: C

    The Host Snapshot feature provides a detailed point-in-time forensic capture of a host's state. This includes a list of running processes, active network connections, loaded drivers, and other critical system information. It is the designated tool for obtaining a comprehensive snapshot for deep analysis without needing a full Real Time Response session.

  5. Question 5Advanced

    Hunting Analytics · Analyze and recognize suspicious overt malicious behaviors

    A hunter is investigating an alert where lsass.exe crashed on a domain controller. The hypothesis is that an attacker attempted to dump credentials. To find the process that interacted with lsass.exe just before the crash, what is the most precise event to search for?

    Show answer & explanation

    Correct answer: C

    Credential dumping tools work by opening a handle to the lsass.exe process and reading its memory. The ProcessAccess event is specifically designed to capture this activity, logging when one process (SourceImageFileName) attempts to access another (TargetImageFileName). Searching for ProcessAccess events where lsass.exe is the target is the most direct way to identify the culprit process.

  6. Question 6BeginnerSelect 2

    Search and Investigation Tools · Interpret search result information displayed in dashboards to determine additional investigation or action

    When triaging a large number of detections, a hunter wants to quickly identify novel or unique threats within their environment. Which two data points in the Falcon detections UI are most useful for this type of prioritization? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Local Prevalence indicates how many hosts within your own organization have seen the detected file or process. A very low number (e.g., 'Unique' or 'Rare') immediately signals that this is not widespread, common software and could be a targeted or new threat deserving higher priority.

    Global Prevalence shows how common the file or process is across the entire CrowdStrike customer base. A low global prevalence suggests the artifact is not a common application and is more likely to be malicious or custom tooling, making it a higher priority for investigation.

  7. Question 7Beginner

    MITRE ATT&CK Frameworks · Operationalize the MITRE ATT&CK Framework to look for research threat models, TTPs and threat actors

    A threat hunter is using the MITRE ATT&CK Framework to structure a hunt for persistence mechanisms. The goal is to find adversaries who may have created new user accounts. Which ATT&CK technique should be the focus of this hunt?

    Show answer & explanation

    Correct answer: B

    T1136: Create Account specifically covers the adversary behavior of creating new local or domain accounts to maintain access to victim systems. This technique falls under the Persistence and Privilege Escalation tactics. A hunt for this technique would involve looking for events related to net user /add commands or other account creation APIs.

  8. Question 8Beginner

    Search and Investigation Tools · Understand use cases for various search options

    True or False: The User Search feature in Falcon can only display activity associated with a user's logon sessions and cannot show processes they have executed.

    Show answer & explanation

    Correct answer: B

    False. The User Search feature is comprehensive. It provides a timeline of a user's activity, including logon events, the hosts they accessed, and a detailed list of the processes they executed. This makes it a powerful tool for investigating user-centric incidents and insider threats.

  9. Question 9Intermediate

    Event Search · Build a query and perform a search using CQL

    A hospital's security team is conducting a threat hunt based on intelligence that a healthcare-targeting adversary group uses scheduled tasks to periodically run a PowerShell-based data staging script. The script is known to use the string 'PatientDataExport' in its command line.

    The CISO has mandated that any findings must be presented in a way that is easily understandable and repeatable for junior analysts. The lead hunter decides to create a saved search that can be run daily.

    Which CQL query should be constructed to effectively find this specific activity?

    sequenceDiagram participant Adversary participant Workstation participant DC as Domain Controller Adversary->>Workstation: Gains Initial Access Workstation->>DC: Creates Scheduled Task (schtasks.exe) DC-->>Workstation: Task Created loop Daily Execution DC->>Workstation: Triggers Scheduled Task Workstation->>Workstation: Executes powershell.exe -file PatientDataExport.ps1 end

    Show answer & explanation

    Correct answer: C

    This query is the most precise and effective. It correctly identifies that scheduled tasks on modern Windows systems are typically launched by svchost.exe (hosting the Task Scheduler service). It filters ProcessRollup2 events for powershell.exe being launched by this parent process and, most importantly, includes the specific keyword *PatientDataExport* in the command line. The table command then formats the output neatly for easy review by junior analysts, fulfilling all requirements.

  10. Question 10Advanced

    Hunting Methodology · Perform outlier analysis with the Falcon tool

    A hunter is performing outlier analysis to find hosts with anomalous network behavior. The goal is to identify endpoints that are communicating with a significantly higher number of distinct IP addresses than their peers. Which CQL query would achieve this?

    Show answer & explanation

    Correct answer: B

    This is the correct approach for outlier analysis in this scenario. It filters for network connection events, then uses stats with the distinct count function dc() on the remote IP address field. It groups the results by ComputerName, effectively counting the number of unique IPs each host connected to. Finally, sort -UniqueIPs orders the results in descending order, bringing the hosts with the most anomalous behavior to the top of the list.

Ready for the real thing?

The full CCFH-202 simulator has every exam-style question, timed mode, and instant scoring.