
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 1Objective 3
1.3 Operationalize the MITRE ATT&CK Framework to Research Threat Models, TTPs and Threat Actors, and Pivot as Necessary and Convey to Non-Technical Audiences CCFH Practice Questions (Page 1)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
19questions here
4free pages
6concepts
Questions 1–5
- 1
While researching a technique, an analyst notices that a specific threat actor group is associated with it. What is the most direct way to pivot from the technique to learn more about that actor?
Select an answer first - 2
A security team is profiling a threat actor that has been observed using a specific dropper and a technique for privilege escalation. The team wants to understand the actor's full capability set to prepare defenses. Which action using ATT&CK is most effective?
Select an answer first - 3
A government contractor is required to assess its security posture against known threat actors that target the defense industrial base. The contractor wants to use MITRE ATT&CK to create a threat model. Which approach is most aligned with this requirement?
Select an answer first - 4
A Falcon Hunter is investigating a series of alerts that show an adversary using a technique for lateral movement. The hunter also notices that the adversary is using a specific tool that is not commonly associated with the technique. The hunter wants to determine if the tool is a custom variant or a known tool. Which approach using ATT&CK is most effective?
Select an answer first - 5
In the MITRE ATT&CK framework, what is the primary purpose of a 'tactic'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.