
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 2
6.2 Identify Suspicious/malicious Activity (IOAs) and Associated Persistence Mechanisms CCCS Practice Questions (Page 7)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
38questions here
8free pages
10concepts
Questions 31–35
- 31
Which action is part of the containment phase when responding to an IOA?
Select an answer first - 32
A security operations center is tuning a detection rule that flags any process that creates a scheduled task. The rule generates many false positives because legitimate software also creates scheduled tasks. Which of the following enhancements would reduce false positives while still detecting malicious scheduled task creation? (Select all that apply.)
Select an answer first - 33
An analyst notices a kernel driver that is not signed by a trusted publisher and is set to load at boot. The driver is not present in the normal driver store. Which persistence mechanism is being used, and what is the most immediate risk?
Select an answer first - 34
An analyst sees an alert where a process dumps the memory of the Local Security Authority Subsystem Service (LSASS) and then uses the extracted credentials to create a new domain account. Which persistence mechanism is being established?
Select an answer first - 35
Which of the following is a common category of suspicious activity that IOA detection is designed to identify?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.