CCFH-202 Sample Questions & Answers
Running searches in the CrowdStrike Query Language carries the top weight, alongside hunting methodology and outlier analysis, pivoting between host and process timelines, applying MITRE's ATT&CK framework with the Cyber Kill Chain, and hunt reports.
Launch the full CCFH-202 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Event Search · Build a query and perform a search using CQL
True or False: The
statscommand in CQL can only be used to count events and cannot calculate other mathematical aggregations like averages or sums.Show answer & explanation
Correct answer: B
The
statscommand is a powerful aggregation tool in CQL. In addition tocount, it supports various other functions, includingavg()for average,sum()for sum,min()for minimum,max()for maximum,dc()for distinct count, andvalues()to list distinct values. - Question 2Advanced
Event Search · Create a custom dashboard to display Advanced Event Search results
A pharmaceutical company is investigating a potential data exfiltration incident. The primary suspect is a disgruntled scientist who recently left the company. The security team believes the scientist may have used a cloud storage synchronization client to upload proprietary research data from their corporate laptop just before their departure.
The security team has the scientist's laptop under forensic hold but first wants to use Falcon to quickly scope the activity across the environment. The known information is the name of a common cloud sync application (
megasync.exe), the user's account name (j.doe), and the timeframe of the activity (the last 48 hours before the account was disabled).The goal is to create a report for management that visualizes the volume of outbound data per host associated with this user and application, to prioritize which other machines might have been compromised or used for exfiltration.
Which approach in Falcon would most efficiently achieve this goal?
Show answer & explanation
Correct answer: D
This is the most direct and efficient method. The CQL query precisely targets the exfiltration activity by filtering for outbound network events (
NetworkSend) from the specific application and user. Usingstats sum(bytes_sent) by ComputerNameaggregates the total data sent from each host, directly answering the core investigative question. Saving this to a custom dashboard provides a clear visualization (like a bar chart) that is perfect for management reporting and prioritizing the investigation on the hosts with the highest exfiltration volumes. - Question 3Intermediate
Event Search · Filter event data and analyze results
A hunter needs to create a CQL query that finds all
FileWrittenevents but excludes any writes to files with.logor.tmpextensions. What is the correct syntax to achieve this?Show answer & explanation
Correct answer: D
This query correctly uses the
searchcommand with theNOToperator to exclude results. TheINoperator allows for checking against a list of values. By combiningNOTandIN, the query efficiently filters out anyFileWrittenevents where theFileNameends in either.logor.tmp. The wildcards*are also correctly used to match any filename. - Question 4Intermediate
Detection Analysis · Analyze information displayed in the Host Timeline to understand host states and events
When analyzing a Host Timeline, a threat hunter needs to understand the state of the host at a specific point in time, including running processes and network connections. Which built-in Falcon feature, accessible from the Host Management page, provides this detailed point-in-time snapshot?
Show answer & explanation
Correct answer: C
The Host Snapshot feature provides a detailed point-in-time forensic capture of a host's state. This includes a list of running processes, active network connections, loaded drivers, and other critical system information. It is the designated tool for obtaining a comprehensive snapshot for deep analysis without needing a full Real Time Response session.
- Question 5Advanced
Hunting Analytics · Analyze and recognize suspicious overt malicious behaviors
A hunter is investigating an alert where
lsass.execrashed on a domain controller. The hypothesis is that an attacker attempted to dump credentials. To find the process that interacted withlsass.exejust before the crash, what is the most precise event to search for?Show answer & explanation
Correct answer: C
Credential dumping tools work by opening a handle to the
lsass.exeprocess and reading its memory. TheProcessAccessevent is specifically designed to capture this activity, logging when one process (SourceImageFileName) attempts to access another (TargetImageFileName). Searching forProcessAccessevents wherelsass.exeis the target is the most direct way to identify the culprit process. - Question 6BeginnerSelect 2
Search and Investigation Tools · Interpret search result information displayed in dashboards to determine additional investigation or action
When triaging a large number of detections, a hunter wants to quickly identify novel or unique threats within their environment. Which two data points in the Falcon detections UI are most useful for this type of prioritization? (Select TWO)
Show answer & explanation
Correct answers: B, D
Local Prevalence indicates how many hosts within your own organization have seen the detected file or process. A very low number (e.g., 'Unique' or 'Rare') immediately signals that this is not widespread, common software and could be a targeted or new threat deserving higher priority.
Global Prevalence shows how common the file or process is across the entire CrowdStrike customer base. A low global prevalence suggests the artifact is not a common application and is more likely to be malicious or custom tooling, making it a higher priority for investigation.
- Question 7Beginner
MITRE ATT&CK Frameworks · Operationalize the MITRE ATT&CK Framework to look for research threat models, TTPs and threat actors
A threat hunter is using the MITRE ATT&CK Framework to structure a hunt for persistence mechanisms. The goal is to find adversaries who may have created new user accounts. Which ATT&CK technique should be the focus of this hunt?
Show answer & explanation
Correct answer: B
T1136: Create Account specifically covers the adversary behavior of creating new local or domain accounts to maintain access to victim systems. This technique falls under the Persistence and Privilege Escalation tactics. A hunt for this technique would involve looking for events related to
net user /addcommands or other account creation APIs. - Question 8Beginner
Search and Investigation Tools · Understand use cases for various search options
True or False: The
User Searchfeature in Falcon can only display activity associated with a user's logon sessions and cannot show processes they have executed.Show answer & explanation
Correct answer: B
False. The User Search feature is comprehensive. It provides a timeline of a user's activity, including logon events, the hosts they accessed, and a detailed list of the processes they executed. This makes it a powerful tool for investigating user-centric incidents and insider threats.
- Question 9Intermediate
Event Search · Build a query and perform a search using CQL
A hospital's security team is conducting a threat hunt based on intelligence that a healthcare-targeting adversary group uses scheduled tasks to periodically run a PowerShell-based data staging script. The script is known to use the string 'PatientDataExport' in its command line.
The CISO has mandated that any findings must be presented in a way that is easily understandable and repeatable for junior analysts. The lead hunter decides to create a saved search that can be run daily.
Which CQL query should be constructed to effectively find this specific activity?
sequenceDiagram participant Adversary participant Workstation participant DC as Domain Controller Adversary->>Workstation: Gains Initial Access Workstation->>DC: Creates Scheduled Task (schtasks.exe) DC-->>Workstation: Task Created loop Daily Execution DC->>Workstation: Triggers Scheduled Task Workstation->>Workstation: Executes powershell.exe -file PatientDataExport.ps1 endShow answer & explanation
Correct answer: C
This query is the most precise and effective. It correctly identifies that scheduled tasks on modern Windows systems are typically launched by
svchost.exe(hosting the Task Scheduler service). It filtersProcessRollup2events forpowershell.exebeing launched by this parent process and, most importantly, includes the specific keyword*PatientDataExport*in the command line. Thetablecommand then formats the output neatly for easy review by junior analysts, fulfilling all requirements. - Question 10Advanced
Hunting Methodology · Perform outlier analysis with the Falcon tool
A hunter is performing outlier analysis to find hosts with anomalous network behavior. The goal is to identify endpoints that are communicating with a significantly higher number of distinct IP addresses than their peers. Which CQL query would achieve this?
Show answer & explanation
Correct answer: B
This is the correct approach for outlier analysis in this scenario. It filters for network connection events, then uses
statswith the distinct count functiondc()on the remote IP address field. It groups the results byComputerName, effectively counting the number of unique IPs each host connected to. Finally,sort -UniqueIPsorders the results in descending order, bringing the hosts with the most anomalous behavior to the top of the list.
Ready for the real thing?
The full CCFH-202 simulator has every exam-style question, timed mode, and instant scoring.