
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 2
6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 4)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
38questions here
8free pages
10concepts
Questions 16–20
- 16
A Falcon alert shows a process attempting to create a new Windows service with a binary path pointing to a file in the Temp directory. The service is set to auto-start. Which persistence mechanism is the attacker attempting to establish?
Select an answer first - 17
During an investigation, an analyst finds that an attacker used a legitimate remote management tool to move laterally and then created a scheduled task on a target host. The scheduled task runs a script that downloads a payload from an external IP. Which chain of events best describes the attack?
Select an answer first - 18
What is the first step in investigating a suspected IOA?
Select an answer first - 19
What is the purpose of persistence in an attacker's methodology?
Select an answer first - 20
How can an attacker achieve persistence by creating a Windows service?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.