Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Cloud Specialist (CCCS)

Domain 6Objective 2

6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 4)

Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.

38questions here
8free pages
10concepts

Questions 16–20

  1. 16application · easy

    A Falcon alert shows a process attempting to create a new Windows service with a binary path pointing to a file in the Temp directory. The service is set to auto-start. Which persistence mechanism is the attacker attempting to establish?

    Select an answer first
  2. 17expert · hard

    During an investigation, an analyst finds that an attacker used a legitimate remote management tool to move laterally and then created a scheduled task on a target host. The scheduled task runs a script that downloads a payload from an external IP. Which chain of events best describes the attack?

    Select an answer first
  3. 18foundation · easy

    What is the first step in investigating a suspected IOA?

    Select an answer first
  4. 19foundation · easy

    What is the purpose of persistence in an attacker's methodology?

    Select an answer first
  5. 20foundation · easy

    How can an attacker achieve persistence by creating a Windows service?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.