Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 6Objective 8

6.8 Identify the Vulnerability Exploited from an Initial Attack Vector CCFH Practice Questions (Page 3)

Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.

15questions here
3free pages
3concepts

Questions 11–15

  1. 11application · medium

    A Falcon analyst is investigating a compromised server. The server is running a web application that uses a database. The analyst sees that the initial access was through a request to a search endpoint, and the response contained data from the database that should not have been accessible. The analyst also sees that a process was spawned from the web application's directory. Which vulnerability was most likely exploited?

    Select an answer first
  2. 12application · medium

    A Falcon analyst is investigating a compromised workstation. The data shows that the initial access was through a remote desktop protocol (RDP) connection from an external IP address. The analyst sees multiple failed logon attempts followed by a successful logon. What is the most likely initial attack vector?

    Select an answer first
  3. 13application · hard

    An analyst is investigating a host that was compromised. The Falcon data shows that the initial process was 'svchost.exe' which made a network connection to an external IP. The analyst also sees that a scheduled task was created that runs a script every hour. The host is a domain controller. Which initial attack vector is most likely?

    Select an answer first
  4. 14application · medium

    An analyst is reviewing an alert where a user received a phone call from someone claiming to be from IT, asking for their password. The user provided the password, and the analyst sees a successful logon from an external IP address shortly after. What is the most likely initial attack vector?

    Select an answer first
  5. 15application · medium

    A Falcon analyst is reviewing an alert where a user on the corporate network visited a website that was flagged as malicious. The analyst sees that the browser process loaded a DLL from the user's temporary folder before making an outbound connection. Which vulnerability was most likely exploited?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.