Free CrowdStrike Certified Falcon Hunter Exam CCFH-202 Exam Practice Test
CCFH-202 Exam Features
In Just $59 You can Access
- All Official Question Types
- Interactive Web-Based Practice Test Software
- No Installation or 3rd Party Software Required
- Customize your practice sessions (Free Demo)
- 24/7 Customer Support
Total Questions: 60
-
Which of the following would be the correct field name to find the name of an event?
Answer: A Next Question -
When performing a raw event search via the Events search page, what are Event Actions?
Answer: C Next Question -
In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
Answer: B Next Question -
Which of the following queries will return the parent processes responsible for launching badprogram exe?
Answer: D Next Question -
What elements are required to properly execute a Process Timeline?
Answer: A Next Question -
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?
Answer: A Next Question -
Where would an analyst find information about shells spawned by root, Kernel Module loads, and wget/curl usage?
Answer: B Next Question -
Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?
Answer: A Next Question -
Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?
Answer: C Next Question -
With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of the following outlines the steps required to properly create a custom alert rule?
Answer: B Next Question
Total Questions: 60