Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Cloud Specialist (CCCS)

Domain 6Objective 2

6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 5)

Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.

38questions here
8free pages
10concepts

Questions 21–25

  1. 21application · medium

    During an incident response, an analyst finds that a malicious DLL is loaded every time a specific user logs on. The DLL is not registered as a service and no scheduled task references it. Which persistence mechanism is most likely being used?

    Select an answer first
  2. 22application · medium

    An organization wants to detect attackers who use legitimate administrative tools to perform malicious actions. Which detection technique is most effective for identifying this type of IOA?

    Select an answer first
  3. 23foundation · easy

    Which IOA is most commonly associated with registry-based persistence?

    Select an answer first
  4. 24foundation · easy

    Which of the following is an account-based persistence mechanism?

    Select an answer first
  5. 25expert · hard

    A security team is evaluating a detection that flags any process that accesses the LSASS process. The team notices a high false-positive rate because legitimate applications also access LSASS for authentication. Which approach would best reduce false positives while still detecting credential theft IOAs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.