
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 2
6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 1)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
38questions here
8free pages
10concepts
Questions 1–5
- 1
Which location is commonly used for file-based persistence?
Select an answer first - 2
An attacker creates a new user account and adds it to the Administrators group. Which persistence mechanism does this IOA map to?
Select an answer first - 3
Which of the following is a persistence mechanism that uses the Windows startup folder?
Select an answer first - 4
During an investigation, an analyst confirms that a compromised host has a malicious scheduled task and a rogue user account. Which sequence of response actions is most appropriate?
Select an answer first - 5
An attacker gains initial access via a phishing email, then uses a scheduled task to run a script that periodically downloads and executes additional payloads. Which IOA category and persistence mechanism pair best matches this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.