CCFH-202 — Free Practice Questions
10 free sample questions from a bank of 131, with the correct answers and explanations. No signup required — start practising right now.
1 Which of the following is a suspicious process behavior?
PowerShell running an execution policy of RemoteSigned An Internet browser (eg., Internet Explorer) performing multiple DNS requests PowerShell launching a PowerShell script Non-network processes (e.g., notepad.exe) making an outbound network connection
Answer: D
2 Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Falcon Event Search?
utc_time conv_time _time time
Answer: C
3 Which of the following would be the correct field name to find the name of an event?
Event_SimpleName Event_Simple_Name EVENT_SIMPLE_NAME event_simpleName
Answer: D
4 Event Search data is recorded with which time zone?
Answer: D
5 Which of the following Event Search queries would only find the DNS lookups to the domain: www.randomdomain.com?
event_simpleName=DnsRequest DomainName=www.randomdomain.com event_simpleName=DnsRequest DomainName=randomdomain.com ComputerName=localhost Dns=randomdomain.com ComputerName=localhost DnsRequest “randomdomain.com”
Answer: A
6 How do you rename fields while using transforming commands such as table, chart, and stats?
By renaming the fields with the “rename” command after the transforming command. e.g. “stats count by ComputerName | rename count AS total_count” You cannot rename fields as it would affect sub-queries and statistical analysis By using the “renamed” keyword after the field name. e.g. “stats count renamed totalcount by ComputerName” By specifying the desired name after the field name. e.g. “stats count totalcount by ComputerName”
Answer: A
7 SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time. Which eval function is correct?
now typeof strftime relative_time
Answer: C
8 Which of the following queries will return the parent processes responsible for launching badprogram.exe?
[search (ParentProcess) where name=badprogram.exe ] | table ParentProcessName _time event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename ParentProcessId_decimal AS TargetProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time [search (ProcessList) where Name=badprogram.exe ] | search ParentProcessName | table ParentProcessName _time event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename TargetProcessId_decimal AS ParentProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time
Answer: B
9 You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?
fields distinctcount table values
Answer: C
10 When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName
The text of the query The results of the Statistics tab No data. Results can only be exported when the “table” command is used All events in the Events tab
Answer: B
Want the full bank of 131 questions for CCFH-202 ? See all practice exams .