
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 2
6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 6)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
38questions here
8free pages
10concepts
Questions 26–30
- 26
A Falcon alert shows a process running with elevated privileges, and shortly after, the same process creates a new local user account and adds it to the Administrators group. Which two IOA categories are most directly demonstrated by this sequence?
Select an answer first - 27
An attacker has gained access to a domain controller and is using a technique to extract password hashes from memory. The attacker then uses those hashes to authenticate to other systems. Which combination of IOA categories and persistence mechanism is most relevant?
Select an answer first - 28
A Falcon alert shows a macro-enabled Office document in the Downloads folder executing a PowerShell command that downloads a script to the AppData\Roaming folder and sets it to run at logon via a registry Run key. Which persistence mechanism is being used?
Select an answer first - 29
An organization wants to detect lateral movement that uses legitimate remote administration tools like PsExec. Which detection strategy would be most effective?
Select an answer first - 30
An incident responder is investigating a host that was compromised two weeks ago. The attacker used a previously unknown exploit to gain admin rights. Which of the following findings would indicate persistence mechanisms that the attacker may have established? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.