CrowdStrike Certified Falcon Hunter
(CCFH-
202b) – Complete Questions with
CORRECT DETAILED 100%ANSWERs
& Rationales
Question 1
Which field in a DNS Request event points to the responsible process?
A. ContextProcessId_readable
B. TargetProcessId_decimal
C. ContextProcessId_decimal
D. ParentProcessId_decimal
CORRECT DETAILED 100%ANSWER: A
The ContextProcessId_readable field in a DNS Request event shows the
readable process identifier of the process that initiated the DNS request. It helps
analysts identify which process communicated with a domain or IP. Other fields,
like TargetProcessId_decimal, ContextProcessId_decimal, and
ParentProcessId_decimal, do not provide the readable process
responsible for the DNS request.
Question 2
What elements are required to properly execute a Process Timeline?
A. Agent ID (AID) and Target Process ID
B. Agent ID (AID) only
C. Hostname and Local Process ID
D. Target Process ID only
,CORRECT DETAILED 100%ANSWER: A
A Process Timeline requires both the Agent ID (AID) of the host and the
Target Process ID. The AID uniquely identifies the Falcon sensor on a host,
and the Target Process ID specifies which process to track. Without both, the
timeline cannot query cloud data for that process.
Question 3
Which of the following is a suspicious process behavior?
A. PowerShell running an execution policy of RemoteSigned
B. An Internet browser performing multiple DNS requests
C. PowerShell launching a PowerShell script
D. Non-network processes (e.g., notepad.exe) making an outbound network
connection CORRECT DETAILED 100%ANSWER: D
Non-network processes like notepad.exe normally should not make outbound
connections. If they do, it can indicate malware or misuse. The other behaviors
listed are normal operations.
Question 4
You need details about key data fields and sensor events which you may expect to
find from hosts running the Falcon sensor. Which documentation should you
access?
A. Events Data Dictionary
B. Streaming API Event Dictionary
C. Hunting and Investigation
D. Event stream APIs
,CORRECT DETAILED 100%ANSWER: A
The Events Data Dictionary details each event type, field name, data type,
description, and examples. This is essential for writing hunting queries and
understanding Falcon event data.
Question 5
The Process Timeline Events Details table will populate the Parent Process ID and
Parent File columns when the cloudable event data contains which event field?
A. ContextProcessId_decimal
B. RawProcessId_decimal
C. ParentProcessId_decimal
D. RpcProcessId_decimal
CORRECT DETAILED 100%ANSWER: C
ParentProcessId_decimal contains the numeric ID of the parent process.
This allows analysts to trace process ancestry and detect malicious activity.
Question 6
What Investigate tool would you use to allow an analyst to view all events for a
specific host?
A. Bulk Timeline
B. Host Search
C. Host Timeline
D. Process Timeline
CORRECT DETAILED 100%ANSWER: C
The Host Timeline visualizes all events on a host over time, allowing filtering
and drill-down. Bulk Timeline and Process Timeline focus on processes, not the
host as a whole.
, Question 7
Which of the following is an example of a Falcon threat hunting lead?
A. A routine threat hunt query showing process executions of single-letter
filenames (e.g., a.exe) from temporary directories
B. Security appliance logs showing potentially bad traffic to an unknown
external IP address
C. A help desk ticket for a user clicking on a link in an email causing their
machine to have high CPU usage
D. An external report describing a unique 5-character file extension for
ransomware-encrypted files
CORRECT DETAILED 100%ANSWER: A
A Falcon threat hunting lead is information used to initiate a hunt within Falcon.
Tracking single-letter process executions in temp directories is a direct lead; the
others are not Falcon-specific.
Question 8
Which field in a network event indicates the remote IP address contacted by a
process?
A. RemoteIpAddress
B. DestIp
C. SourceIp
D. ConnectionIp
CORRECT DETAILED 100%ANSWER: A
The RemoteIpAddress field shows the IP address that the process
communicated with. This is critical for tracking suspicious connections or potential
command-and-control activity. DestIp and SourceIp may appear in raw logs
but are not standard Falcon event fields for this purpose.
(CCFH-
202b) – Complete Questions with
CORRECT DETAILED 100%ANSWERs
& Rationales
Question 1
Which field in a DNS Request event points to the responsible process?
A. ContextProcessId_readable
B. TargetProcessId_decimal
C. ContextProcessId_decimal
D. ParentProcessId_decimal
CORRECT DETAILED 100%ANSWER: A
The ContextProcessId_readable field in a DNS Request event shows the
readable process identifier of the process that initiated the DNS request. It helps
analysts identify which process communicated with a domain or IP. Other fields,
like TargetProcessId_decimal, ContextProcessId_decimal, and
ParentProcessId_decimal, do not provide the readable process
responsible for the DNS request.
Question 2
What elements are required to properly execute a Process Timeline?
A. Agent ID (AID) and Target Process ID
B. Agent ID (AID) only
C. Hostname and Local Process ID
D. Target Process ID only
,CORRECT DETAILED 100%ANSWER: A
A Process Timeline requires both the Agent ID (AID) of the host and the
Target Process ID. The AID uniquely identifies the Falcon sensor on a host,
and the Target Process ID specifies which process to track. Without both, the
timeline cannot query cloud data for that process.
Question 3
Which of the following is a suspicious process behavior?
A. PowerShell running an execution policy of RemoteSigned
B. An Internet browser performing multiple DNS requests
C. PowerShell launching a PowerShell script
D. Non-network processes (e.g., notepad.exe) making an outbound network
connection CORRECT DETAILED 100%ANSWER: D
Non-network processes like notepad.exe normally should not make outbound
connections. If they do, it can indicate malware or misuse. The other behaviors
listed are normal operations.
Question 4
You need details about key data fields and sensor events which you may expect to
find from hosts running the Falcon sensor. Which documentation should you
access?
A. Events Data Dictionary
B. Streaming API Event Dictionary
C. Hunting and Investigation
D. Event stream APIs
,CORRECT DETAILED 100%ANSWER: A
The Events Data Dictionary details each event type, field name, data type,
description, and examples. This is essential for writing hunting queries and
understanding Falcon event data.
Question 5
The Process Timeline Events Details table will populate the Parent Process ID and
Parent File columns when the cloudable event data contains which event field?
A. ContextProcessId_decimal
B. RawProcessId_decimal
C. ParentProcessId_decimal
D. RpcProcessId_decimal
CORRECT DETAILED 100%ANSWER: C
ParentProcessId_decimal contains the numeric ID of the parent process.
This allows analysts to trace process ancestry and detect malicious activity.
Question 6
What Investigate tool would you use to allow an analyst to view all events for a
specific host?
A. Bulk Timeline
B. Host Search
C. Host Timeline
D. Process Timeline
CORRECT DETAILED 100%ANSWER: C
The Host Timeline visualizes all events on a host over time, allowing filtering
and drill-down. Bulk Timeline and Process Timeline focus on processes, not the
host as a whole.
, Question 7
Which of the following is an example of a Falcon threat hunting lead?
A. A routine threat hunt query showing process executions of single-letter
filenames (e.g., a.exe) from temporary directories
B. Security appliance logs showing potentially bad traffic to an unknown
external IP address
C. A help desk ticket for a user clicking on a link in an email causing their
machine to have high CPU usage
D. An external report describing a unique 5-character file extension for
ransomware-encrypted files
CORRECT DETAILED 100%ANSWER: A
A Falcon threat hunting lead is information used to initiate a hunt within Falcon.
Tracking single-letter process executions in temp directories is a direct lead; the
others are not Falcon-specific.
Question 8
Which field in a network event indicates the remote IP address contacted by a
process?
A. RemoteIpAddress
B. DestIp
C. SourceIp
D. ConnectionIp
CORRECT DETAILED 100%ANSWER: A
The RemoteIpAddress field shows the IP address that the process
communicated with. This is critical for tracking suspicious connections or potential
command-and-control activity. DestIp and SourceIp may appear in raw logs
but are not standard Falcon event fields for this purpose.