
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 5
6.5 Decode and Understand PowerShell/CMD Activity CCFH Practice Questions (Page 5)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
23questions here
5free pages
8concepts
Questions 21–23
- 21
A threat hunter is analyzing a CMD process that shows the command line `cmd.exe /c "for /f "tokens=*" %i in ('dir /b C:\Users\Public\*.bat') do @call %i"`. What is the most likely purpose of this command?
Select an answer first - 22
A security team is reviewing a PowerShell script that was executed via a scheduled task. The script is signed with a valid certificate, but the execution policy on the host is `AllSigned`. The script runs successfully. Which statement best explains why the script executed?
Select an answer first - 23
A threat hunter is investigating a CMD process that shows the command line `cmd.exe /c "echo @echo off > C:\Users\Public\a.bat & echo whoami >> C:\Users\Public\a.bat & echo ipconfig >> C:\Users\Public\a.bat"`. What is the primary purpose of this command?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.