
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 7Objective 1
7.1 Identify Recommended Remediation Steps for Findings and Detections CCCS Practice Questions (Page 2)
Part of the Remediating and Reporting Issues domain, which makes up ~9% of our current practice bank.
22questions here
5free pages
3concepts
Questions 6–10
- 6
A security analyst must remediate two detections: a high-severity ransomware on a file server and a medium-severity credential theft on a domain controller. The file server is already isolated. The domain controller is not isolated. Which action should the analyst take first?
Select an answer first - 7
An organization has a limited security team and must remediate multiple detections. Which approach should they take to prioritize remediation actions?
Select an answer first - 8
A finding shows that a host has a known vulnerability in a third-party application. The vendor has not released a patch yet. What is the recommended remediation step?
Select an answer first - 9
A detection shows that a host is attempting to communicate with a known malicious IP address. The host is a critical database server that cannot be isolated. What is the recommended remediation step?
Select an answer first - 10
A security team has three detections: a low-severity adware on a kiosk, a medium-severity phishing email that was opened by a user, and a high-severity ransomware on a file server. The file server is already isolated. Which detection should be remediated next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.