CCFH-202 Exam QuestionsBrowse all questions from this exam

CCFH-202 Exam - Question 42


In the Powershell Hunt report, what does the “score” signify?

Show Answer
Correct Answer: D

In the PowerShell Hunt report, the 'score' signifies a cumulative score of the various potential command line switches. This score is determined by evaluating the presence and combination of different command-line switches that may indicate suspicious or malicious activity.

Discussion

3 comments
Sign in to comment
Jimmy390Option: D
Oct 2, 2023

Checked falcon console, appears to be D

ChiquitabanditaOption: D
Sep 10, 2023

this one seems most likely and couldnt find info on the other choices

VasiOnCacaoOption: C
Dec 25, 2023

Actually I am for the C here. https://www.crowdstrike.com/blog/tech-center/powershell-hunting/ Listen to what they say about the score field at around the end. Looks more logical to me.

gr23
Jan 11, 2024

But it doesn't use NGAV to do that. Trick answer. The correct answer is D. Different CLI switches have different ratings ergo different scores. This is in the documentation.