
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 5
6.5 Decode and Understand PowerShell/CMD Activity CCFH Practice Questions (Page 2)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
23questions here
5free pages
8concepts
Questions 6–10
- 6
An analyst finds a PowerShell command that includes `-Command` with the string `$s=New-Object System.IO.MemoryStream(,[Convert]::FromBase64String('H4sIAAAAAAA...'));IEX(New-Object System.IO.StreamReader($s)).ReadToEnd()`. What is the most likely purpose of this command?
Select an answer first - 7
A Falcon Hunter encounters a PowerShell command that uses `[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String(...))`. What is the primary purpose of this code?
Select an answer first - 8
Which PowerShell cmdlet is commonly used to download a file from a remote URL?
Select an answer first - 9
A security analyst is investigating a PowerShell process that ran with the command line `powershell.exe -ExecutionPolicy Bypass -File C:\Users\Public\script.ps1`. The host's effective execution policy is `Restricted`. The script runs successfully. Which statement best explains why the script executed?
Select an answer first - 10
A Falcon event shows a CMD process with the command line `cmd.exe /c "net user hacker P@ssw0rd! /add & net localgroup administrators hacker /add"`. What is the most likely goal of this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.