
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 8
6.8 Identify the Vulnerability Exploited from an Initial Attack Vector CCFH Practice Questions (Page 1)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
15questions here
3free pages
3concepts
Questions 1–5
- 1
A user receives a spearphishing email with a malicious attachment. After the user opens the attachment, the attacker gains initial access. Which of the following best describes the initial attack vector?
Select an answer first - 2
An analyst is reviewing an alert where a user received an email with a link to a website that hosted a malicious JavaScript. The user visited the website, and the JavaScript exploited a vulnerability in the browser to execute code. The Falcon data shows that the browser process spawned a child process. Which initial attack vector is most likely?
Select an answer first - 3
A Falcon analyst is investigating a compromised workstation. The data shows that the initial process was 'winword.exe', which then spawned 'powershell.exe'. The analyst also sees that the user had previously opened a document from a shared network drive. The document was not from an external source. Which initial attack vector is most likely?
Select an answer first - 4
An analyst observes that an attacker exploited a vulnerability in an Internet-facing web server to execute commands. Which initial attack vector is indicated by this evidence?
Select an answer first - 5
A Falcon analyst observes a server that is directly exposed to the internet. The server is running an outdated version of a web application. The analyst sees a series of HTTP requests with unusual SQL syntax in the URL parameters, followed by a process spawning from the web server's working directory. Which vulnerability was most likely exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.