Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Cloud Specialist (CCCS)

Domain 6Objective 2

6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 2)

Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.

38questions here
8free pages
10concepts

Questions 6–10

  1. 6expert · hard

    An incident response team is responding to a breach where the attacker has established persistence via a scheduled task and a rogue service. The team needs to eradicate the threat while minimizing business disruption. Which approach is most appropriate?

    Select an answer first
  2. 7application · medium

    A security analyst reviews Falcon alerts and sees a single process spawning multiple child processes, each attempting to authenticate to different internal hosts using stolen credentials. No known malicious file hashes are detected. Which statement best describes why this activity is classified as an IOA rather than an IOC?

    Select an answer first
  3. 8foundation · easy

    How does behavioral analytics contribute to IOA detection?

    Select an answer first
  4. 9application · easy

    An analyst observes a process writing a PowerShell script to the current user's Startup folder and then creating a scheduled task that runs the same script every hour. Which two persistence mechanisms are being used?

    Select an answer first
  5. 10foundation · easy

    What is a kernel driver persistence mechanism?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.