
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 5
6.5 Decode and Understand PowerShell/CMD Activity CCFH Practice Questions (Page 4)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
23questions here
5free pages
8concepts
Questions 16–20
- 16
A Falcon alert shows a CMD process with the command line `reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Windows\System32\cmd.exe /c powershell -enc <base64>" /f`. What is the primary goal of this command?
Select an answer first - 17
A hunting hypothesis is 'An attacker is using CMD to perform network reconnaissance.' Which decoded command line would most directly support this hypothesis?
Select an answer first - 18
What is the primary difference between a CMD batch file and an inline CMD command?
Select an answer first - 19
In a CMD batch file, what does the `@echo off` line do?
Select an answer first - 20
Which CMD command is used to display the network configuration, including IP addresses and network adapters?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.