
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 8
6.8 Identify the Vulnerability Exploited from an Initial Attack Vector CCFH Practice Questions (Page 2)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
15questions here
3free pages
3concepts
Questions 6–10
- 6
A Falcon analyst is investigating a compromised web server. The server is running a custom web application and is behind a WAF. The analyst sees that the WAF logged a request with a payload that bypassed the WAF rules. The request was a POST to a file upload endpoint, and the response was a 200 OK. The analyst also sees that a process was spawned from the web root. Which vulnerability was most likely exploited?
Select an answer first - 7
A Falcon administrator investigates an alert where a workstation established an outbound connection to a known malicious IP immediately after the user clicked a link in a phishing email. The connection occurred over port 443, and the process was a legitimate web browser. Reviewing the Falcon event data, the administrator sees the browser spawned a child process that was not a standard browser helper. Which vulnerability was most likely exploited as the initial attack vector?
Select an answer first - 8
An organization has a mix of legacy and modern systems. A legacy server running an outdated version of a database application is compromised. The Falcon data shows that the initial access was through a network connection to the database port, and the attacker was able to execute commands on the server. The analyst also notes that the server is not exposed to the internet but is on the internal network. Which vulnerability was most likely exploited?
Select an answer first - 9
An attacker exploits a SQL injection vulnerability in a web application to extract sensitive data. Which vulnerability was exploited?
Select an answer first - 10
A Falcon analyst is investigating a compromised host that is part of a critical infrastructure environment. The host is not directly exposed to the internet but is accessible from a jump box. The analyst sees that the initial access was through a connection from the jump box, and the process that executed code was 'cmd.exe'. The analyst also notes that the jump box was recently compromised. Which initial attack vector is most likely?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.