Sign In
Home/CrowdStrike/CCFH-202/Free questions

CCFH-202 — Free Practice Questions

10 free sample questions from a bank of 131, with the correct answers and explanations. No signup required — start practising right now.

1Which of the following is a suspicious process behavior?
  • PowerShell running an execution policy of RemoteSigned
  • An Internet browser (eg., Internet Explorer) performing multiple DNS requests
  • PowerShell launching a PowerShell script
  • Non-network processes (e.g., notepad.exe) making an outbound network connection
Answer: D
2Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Falcon Event Search?
  • utc_time
  • conv_time
  • _time
  • time
Answer: C
3Which of the following would be the correct field name to find the name of an event?
  • Event_SimpleName
  • Event_Simple_Name
  • EVENT_SIMPLE_NAME
  • event_simpleName
Answer: D
4Event Search data is recorded with which time zone?
  • PST
  • GMT
  • EST
  • UTC
Answer: D
5Which of the following Event Search queries would only find the DNS lookups to the domain: www.randomdomain.com?
  • event_simpleName=DnsRequest DomainName=www.randomdomain.com
  • event_simpleName=DnsRequest DomainName=randomdomain.com ComputerName=localhost
  • Dns=randomdomain.com
  • ComputerName=localhost DnsRequest “randomdomain.com”
Answer: A
6How do you rename fields while using transforming commands such as table, chart, and stats?
  • By renaming the fields with the “rename” command after the transforming command. e.g. “stats count by ComputerName | rename count AS total_count”
  • You cannot rename fields as it would affect sub-queries and statistical analysis
  • By using the “renamed” keyword after the field name. e.g. “stats count renamed totalcount by ComputerName”
  • By specifying the desired name after the field name. e.g. “stats count totalcount by ComputerName”
Answer: A
7SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time. Which eval function is correct?
  • now
  • typeof
  • strftime
  • relative_time
Answer: C
8Which of the following queries will return the parent processes responsible for launching badprogram.exe?
  • [search (ParentProcess) where name=badprogram.exe ] | table ParentProcessName _time
  • event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename ParentProcessId_decimal AS TargetProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time
  • [search (ProcessList) where Name=badprogram.exe ] | search ParentProcessName | table ParentProcessName _time
  • event_simpleName=processrollup2 [search event_simpleName=processrollup2 FileName=badprogram.exe | rename TargetProcessId_decimal AS ParentProcessId_decimal | fields aid TargetProcessId_decimal] | stats count by FileName _time
Answer: B
9You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?
  • fields
  • distinctcount
  • table
  • values
Answer: C
10When exporting the results of the following event search, what data is saved in the exported file (assuming Verbose Mode)? event_simpleName=*Written | stats count by ComputerName
  • The text of the query
  • The results of the Statistics tab
  • No data. Results can only be exported when the “table” command is used
  • All events in the Events tab
Answer: B

Want the full bank of 131 questions for CCFH-202? See all practice exams.