Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Cloud Specialist (CCCS)

Domain 6Objective 2

6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 1)

Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.

38questions here
8free pages
10concepts

Questions 1–5

  1. 1foundation · easy

    Which location is commonly used for file-based persistence?

    Select an answer first
  2. 2foundation · easy

    An attacker creates a new user account and adds it to the Administrators group. Which persistence mechanism does this IOA map to?

    Select an answer first
  3. 3foundation · easy

    Which of the following is a persistence mechanism that uses the Windows startup folder?

    Select an answer first
  4. 4application · medium

    During an investigation, an analyst confirms that a compromised host has a malicious scheduled task and a rogue user account. Which sequence of response actions is most appropriate?

    Select an answer first
  5. 5application · medium

    An attacker gains initial access via a phishing email, then uses a scheduled task to run a script that periodically downloads and executes additional payloads. Which IOA category and persistence mechanism pair best matches this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.