
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 8
6.8 Identify the Vulnerability Exploited from an Initial Attack Vector CCFH Practice Questions (Page 3)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
15questions here
3free pages
3concepts
Questions 11–15
- 11
A Falcon analyst is investigating a compromised server. The server is running a web application that uses a database. The analyst sees that the initial access was through a request to a search endpoint, and the response contained data from the database that should not have been accessible. The analyst also sees that a process was spawned from the web application's directory. Which vulnerability was most likely exploited?
Select an answer first - 12
A Falcon analyst is investigating a compromised workstation. The data shows that the initial access was through a remote desktop protocol (RDP) connection from an external IP address. The analyst sees multiple failed logon attempts followed by a successful logon. What is the most likely initial attack vector?
Select an answer first - 13
An analyst is investigating a host that was compromised. The Falcon data shows that the initial process was 'svchost.exe' which made a network connection to an external IP. The analyst also sees that a scheduled task was created that runs a script every hour. The host is a domain controller. Which initial attack vector is most likely?
Select an answer first - 14
An analyst is reviewing an alert where a user received a phone call from someone claiming to be from IT, asking for their password. The user provided the password, and the analyst sees a successful logon from an external IP address shortly after. What is the most likely initial attack vector?
Select an answer first - 15
A Falcon analyst is reviewing an alert where a user on the corporate network visited a website that was flagged as malicious. The analyst sees that the browser process loaded a DLL from the user's temporary folder before making an outbound connection. Which vulnerability was most likely exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.