
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 2
6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 5)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
38questions here
8free pages
10concepts
Questions 21–25
- 21
During an incident response, an analyst finds that a malicious DLL is loaded every time a specific user logs on. The DLL is not registered as a service and no scheduled task references it. Which persistence mechanism is most likely being used?
Select an answer first - 22
An organization wants to detect attackers who use legitimate administrative tools to perform malicious actions. Which detection technique is most effective for identifying this type of IOA?
Select an answer first - 23
Which IOA is most commonly associated with registry-based persistence?
Select an answer first - 24
Which of the following is an account-based persistence mechanism?
Select an answer first - 25
A security team is evaluating a detection that flags any process that accesses the LSASS process. The team notices a high false-positive rate because legitimate applications also access LSASS for authentication. Which approach would best reduce false positives while still detecting credential theft IOAs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.