New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFH-202b Exam - Topic 7 Question 2 Discussion

Actual exam question for CrowdStrike's CCFH-202b exam
Question #: 2
Topic #: 7
[All CCFH-202b Questions]

The help desk is reporting an increase in calls related to user accounts being locked out over the last few days. You suspect that this could be an attack by an adversary against your organization. Select the best hunting hypothesis from the following:

Show Suggested Answer Hide Answer
Suggested Answer: D

A hunting hypothesis is a statement that describes a possible malicious activity that can be tested with data and analysis. A good hunting hypothesis should be specific, testable, and relevant to the problem or goal. In this case, the best hunting hypothesis from the following is that a password guessing attack is being executed against remote access mechanisms such as VPN, as it explains the possible cause and method of the user account lockouts in a specific and testable way. A zero-day vulnerability on a Microsoft Exchange server is too vague and does not explain how it relates to the lockouts. A hacked web application is also too vague and does not specify how it causes the lockouts. Users locking their accounts out because they recently changed their passwords is not a malicious activity and does not account for the increase in calls.


Contribute your Thoughts:

0/2000 characters
Lonna
8 days ago
I'm not sure if the recent password changes could be causing the lockouts, but it feels like a common issue we studied.
upvoted 0 times
...
Denise
13 days ago
I remember discussing how password guessing attacks can lead to account lockouts, especially with VPNs. That seems like a strong possibility here.
upvoted 0 times
...
Lavera
18 days ago
I'm pretty confident that option D is the correct answer. A password guessing attack on the remote access mechanisms seems like the most logical explanation for the account lockouts.
upvoted 0 times
...
Tess
23 days ago
I think the best approach is to start by investigating the web application mentioned in option B. That could be a good place to start narrowing down the issue.
upvoted 0 times
...
Elenore
28 days ago
I'm a bit confused here. Could it also be that users are just forgetting their new passwords? Option C seems plausible too.
upvoted 0 times
...
Josefa
1 month ago
Okay, let's see. I'm leaning towards option D - a password guessing attack on the VPN. That seems like the most likely scenario based on the information provided.
upvoted 0 times
...
Stephane
1 month ago
Hmm, this is a tricky one. I'm not sure if it's a zero-day vulnerability or a password guessing attack. I'll need to think this through carefully.
upvoted 0 times
...

Save Cancel