Crowdstrike

CCFH-202 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 82-question bank.

Provider
Crowdstrike
Question bank
82
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CCFH-202, a certification listed under Crowdstrike. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Crowdstrike. The certification credential is issued by Crowdstrike, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following is a suspicious process behavior?

    Choose one answer.

    • PowerShell running an execution policy of RemoteSigned
    • An Internet browser (eg., Internet Explorer) performing multiple DNS requests
    • PowerShell launching a PowerShell script
    • Non-network processes (e.g., notepad.exe) making an outbound network connection
  2. Question 2 · 1

    Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Falcon Event Search?

    Choose one answer.

    • utc_time
    • conv_time
    • _time
    • time
  3. Question 3 · 1

    Which of the following would be the correct field name to find the name of an event?

    Choose one answer.

    • Event_SimpleName
    • Event_Simple_Name
    • EVENT_SIMPLE_NAME
    • event_simpleName
  4. Question 4 · 1

    Event Search data is recorded with which time zone?

    Choose one answer.

    • PST
    • GMT
    • EST
    • UTC
  5. Question 5 · 1

    How do you rename fields while using transforming commands such as table, chart, and stats?

    Choose one answer.

    • By renaming the fields with the “rename” command after the transforming command. e.g. “stats count by ComputerName | rename count AS total_count”
    • You cannot rename fields as it would affect sub-queries and statistical analysis
    • By using the “renamed” keyword after the field name. e.g. “stats count renamed totalcount by ComputerName”
    • By specifying the desired name after the field name. e.g. “stats count totalcount by ComputerName”
  6. Question 6 · 1

    SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time. Which eval function is correct?

    Choose one answer.

    • now
    • typeof
    • strftime
    • relative_time
  7. Question 7 · 1

    Which of the following queries will return the parent processes responsible for launching badprogram.exe?

    Choose one answer.

    • [search (ParentProcess) where name=badprogram.exe ] | table ParentProcessName _time
    • event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename ParentProcessId_decimal AS TargetProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time
    • [search (ProcessList) where Name=badprogram.exe ] | search ParentProcessName | table ParentProcessName _time
    • event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename TargetProcessId_decimal AS ParentProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time
  8. Question 8 · 1

    You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?

    Choose one answer.

    • fields
    • distinctcount
    • table
    • values
  9. Question 9 · 1

    When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName

    Choose one answer.

    • The text of the query
    • The results of the Statistics tab
    • No data. Results can only be exported when the “table” command is used
    • All events in the Events tab
  10. Question 10 · 1

    The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against your organization. Select the best hunting hypothesis from the following:

    Choose one answer.

    • A zero-day vulnerability is being exploited on a Microsoft Exchange server
    • A publicly available web application has been hacked and is causing the lockouts
    • Users are locking their accounts out because they recently changed their passwords
    • A password guessing attack is being executed against remote access mechanisms such as VPN
  11. Question 11 · 1

    Which field should you reference in order to find the system time of a *FileWritten event?

    Choose one answer.

    • ContextTimeStamp_decimal
    • FileTimeStamp_decimal
    • ProcessStartTime_decimal
    • timestamp
  12. Question 12 · 1

    To find events that are outliers inside a network, ___________is the best hunting method to use.

    Choose one answer.

    • time-based
    • machine learning
    • searching
    • stacking
  13. Question 13 · 1

    Which of the following is a way to create event searches that run automatically and recur on a schedule that you set?

    Choose one answer.

    • Workflows
    • Event Search
    • Scheduled Searches
    • Scheduled Reports
  14. Question 14 · 1

    Which of the following is a recommended technique to find unique outliers among a set of data in the Falcon Event Search?

    Choose one answer.

    • Hunt-and-Peck Search Methodology
    • Stacking (Frequency Analysis)
    • Time-based Searching
    • Machine Learning
  15. Question 15 · 1

    Adversaries commonly execute discovery commands such as net.exe, ipconfig.exe, and whoami.exe. Rather than query for each of these commands individually, you would like to use a single query with all of them. What Splunk operator is needed to complete the following query? aid=my-aid event_simpleName=ProcessRollup2 (FileName=net.exe __________ FileName=ipconfig.exe _________ FileName=whoami.exe) | table ComputerName UserName FileName CommandLine

    Choose one answer.

    • OR
    • IN
    • NOT
    • AND

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free