Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 6Objective 5

6.5 Decode and Understand PowerShell/CMD Activity CCFH Practice Questions (Page 5)

Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.

23questions here
5free pages
8concepts

Questions 21–23

  1. 21expert · hard

    A threat hunter is analyzing a CMD process that shows the command line `cmd.exe /c "for /f "tokens=*" %i in ('dir /b C:\Users\Public\*.bat') do @call %i"`. What is the most likely purpose of this command?

    Select an answer first
  2. 22application · medium

    A security team is reviewing a PowerShell script that was executed via a scheduled task. The script is signed with a valid certificate, but the execution policy on the host is `AllSigned`. The script runs successfully. Which statement best explains why the script executed?

    Select an answer first
  3. 23application · medium

    A threat hunter is investigating a CMD process that shows the command line `cmd.exe /c "echo @echo off > C:\Users\Public\a.bat & echo whoami >> C:\Users\Public\a.bat & echo ipconfig >> C:\Users\Public\a.bat"`. What is the primary purpose of this command?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.