Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
What topics are presented in the Hunting and Investigation Guide?
This is the correct answer for the same reason as above. The Hunting and Investigation guide provides sample hunting queries, select walkthroughs, and best practices for hunting with Falcon. It does not provide a detailed tutorial on writing advanced queries, a detailed summary of event names and descriptions, or recommended platform configurations and prevention settings.
Which threat framework allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies?
MITRE ATT&CK is a threat framework that allows a threat hunter to explore and model specific adversary tactics and techniques, with links to intelligence and case studies. It is a knowledge base of adversary behaviors and tactics that covers various platforms, domains, and scenarios. It provides a common language and structure for threat hunters to understand and analyze threats, as well as to share findings and recommendations.
What Investigate tool would you use to allow an analyst to view all events for a specific host?
The Host Timeline is the Investigate tool that you would use to allow an analyst to view all events for a specific host. The Host Timeline shows a graphical representation of all events that occurred on a host within a specified time range. It allows an analyst to zoom in and out, filter by event type or name, and drill down into event details. The Bulk Timeline, the Host Search, and the Process Timeline are not Investigate tools that you would use to view all events for a specific host.
Which of the following best describes the purpose of the Mac Sensor report?
This is the correct answer for the same reason as above. The Mac Sensor report provides a comprehensive view of activities occurring on Mac hosts, including items of interest that may be hunting or investigation leads. It does not display a listing of all Mac hosts with or without a Falcon sensor installed, nor does it provide a detection focused view of known malicious activities occurring on Mac hosts.
Which of the following is an example of a Falcon threat hunting lead?
A Falcon threat hunting lead is a piece of information that can be used to initiate or guide a threat hunting activity within the Falcon platform. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories is an example of a Falcon threat hunting lead, as it can indicate potential malicious activity that can be further investigated using Falcon data and features. Security appliance logs, help desk tickets, and external reports are not examples of Falcon threat hunting leads, as they are not directly related to the Falcon platform or data.
60 questions covering all exam domains, starting from $20
Exam domains verified against: Official CrowdStrike CCFH-202b exam guide, last checked September 2026.
Understand the cyber kill chain phases and use MITRE ATT&CK to model threat actor behaviors. Apply this framework to identify intelligence gaps and communicate threat research findings to both technical and non-technical audiences.
Interpret Host Timeline and Process Timeline events to understand system states and behavioral sequences. Pivot from detection alerts into deeper investigative tools to expand your analysis.
Analyze file and process metadata in Falcon and choose the right investigation module tool for each scenario. Apply User Search, Host Search, Hash Search, IP search, and Domain Search effectively to guide next steps.
Build queries using CrowdStrike Query Language syntax to search events, filter results, and understand process relationships. Export and format data for analysis and create custom dashboards from Advanced Event Search results.
Use Hunt reports and Visibility reports to refine findings and uncover patterns. Reference the Events Full Reference documentation to understand specific event types in detail.
Recognize malicious behaviors in raw data and distinguish them from legitimate activity. Decode PowerShell and command-line activity, identify exploited vulnerabilities, and apply statistical methods to reduce false positives.
Run active hunts to detect breaches and conduct outlier analysis using Falcon. Develop hypotheses, generate hunting leads, write complex queries, and investigate full process trees to find root causes.
Sample question from this domain above: Q5
Common questions about the exam itself