Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFH-202b Exam - Topic 6 Question 15 Discussion

Which of the following is a suspicious process behavior?
D) Non-network processes (eg, notepad exe) making an outbound network connection
A) PowerShell running an execution policy of RemoteSigned
B) An Internet browser (eg, Internet Explorer) performing multiple DNS requests
C) PowerShell launching a PowerShell script

CrowdStrike CCFH-202b Exam - Topic 6 Question 15 Discussion

Actual exam question for CrowdStrike's CCFH-202b exam
Question #: 15
Topic #: 6
[All CCFH-202b Questions]

Which of the following is a suspicious process behavior?

Show Suggested Answer Hide Answer
Suggested Answer: D

Non-network processes are processes that are not expected to communicate over the network, such as notepad.exe. If they make an outbound network connection, it could indicate that they are compromised or maliciously used by an adversary. PowerShell running an execution policy of RemoteSigned is a default setting that allows local scripts to run without digital signatures. An Internet browser performing multiple DNS requests is a normal behavior for web browsing. PowerShell launching a PowerShell script is also a common behavior for legitimate tasks.


Contribute your Thoughts:

0/2000 characters
Ricki
4 days ago
C is just PowerShell doing its thing, nothing weird there.
upvoted 0 times
...
Rory
9 days ago
B could be normal, browsers do that sometimes.
upvoted 0 times
...
Carlton
14 days ago
Wait, why would Notepad connect to the internet?
upvoted 0 times
...
Sanjuana
19 days ago
A seems fine, RemoteSigned is common.
upvoted 0 times
...
Celeste
24 days ago
D is definitely suspicious!
upvoted 0 times
...
Crista
30 days ago
PowerShell launching a script seems common, but I can't recall if that alone is a red flag.
upvoted 0 times
...
Buddy
1 month ago
I feel like multiple DNS requests from a browser could be normal behavior, but it might depend on the context.
upvoted 0 times
...
Robt
1 month ago
I think we practiced a similar question about processes making outbound connections. Non-network processes doing that seems really odd to me.
upvoted 0 times
...
Lashawna
2 months ago
I remember discussing how PowerShell can be used for both legitimate and malicious purposes, but I'm not sure if RemoteSigned is inherently suspicious.
upvoted 0 times
...

Save Cancel