Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free CrowdStrike CCFH-202 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following Event Search queries would only find the DNS lookups to the domain: www randomdomain com?

Options:
A.

event_simpleName=DnsRequest DomainName=www randomdomain com

B.

event_simpleName=DnsRequest DomainName=randomdomain com ComputerName=localhost

C.

Dns=randomdomain com

D.

ComputerName=localhost DnsRequest "randomdomain com"

CrowdStrike CCFH-202 Premium Access
Questions 12

Which of the following would be the correct field name to find the name of an event?

Options:
A.

Event_SimpleName

B.

Event_Simple_Name

C.

EVENT_SIMPLE_NAME

D.

event_simpleName

Questions 13

Which of the following best describes the purpose of the Mac Sensor report?

Options:
A.

The Mac Sensor report displays a listing of all Mac hosts without a Falcon sensor installed

B.

The Mac Sensor report provides a detection focused view of known malicious activities occurring on Mac hosts, including machine-learning and indicator-based detections

C.

The Mac Sensor report displays a listing of all Mac hosts with a Falcon sensor installed

D.

The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads

Questions 14

Which of the following is the proper method to quantify search results, enabling a hunter to quickly sort and identify outliers?

Options:
A.

Using the "| stats count by" command at the end of a search string in Event Search

B.

Using the "|stats count" command at the end of a search string in Event Search

C.

Using the "|eval" command at the end of a search string in Event Search

D.

Exporting Event Search results to a spreadsheet and aggregating the results

Questions 15

When performing a raw event search via the Events search page, what are Event Actions?

Options:
A.

Event Actions contains an audit information log of actions an analyst took in regards to a specific detection

B.

Event Actions contains the summary of actions taken by the Falcon sensor such as quarantining a file, prevent a process from executing or taking no actions and creating a detection only

C.

Event Actions are pivotable workflows including connecting to a host, pre-made event searches and pivots to other investigatory pages such as host search

D.

Event Actions is the field name that contains the event name defined in the Events Data Dictionary such as ProcessRollup, SyntheticProcessRollup, DNS request, etc

Questions 16

What information is provided when using IP Search to look up an IP address?

Options:
A.

Both internal and external IPs

B.

Suspicious IP addresses

C.

External IPs only

D.

Internal IPs only

Questions 17

The Falcon Detections page will attempt to decode Encoded PowerShell Command line parameters when which PowerShell Command line parameter is present?

Options:
A.

-Command

B.

-Hidden

C.

-e

D.

-nop

Questions 18

Which of the following is an example of a Falcon threat hunting lead?

Options:
A.

A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories

B.

Security appliance logs showing potentially bad traffic to an unknown external IP address

C.

A help desk ticket for a user clicking on a link in an email causing their machine to become unresponsive and have high CPU usage

D.

An external report describing a unique 5 character file extension for ransomware encrypted files

Exam Code: CCFH-202
Certification Provider: CrowdStrike
Exam Name: CrowdStrike Certified Falcon Hunter
Last Update: Jul 16, 2025
Questions: 60
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

CrowdStrike Related Exams

CrowdStrike Free Exams

CrowdStrike Free Exams
Examstrack provides free CrowdStrike exam prep materials and practice tests to support your CrowdStrike certification goals.