
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 1Objective 3
1.3 Operationalize the MITRE ATT&CK Framework to Research Threat Models, TTPs and Threat Actors, and Pivot as Necessary and Convey to Non-Technical Audiences CCFH Practice Questions (Page 3)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
19questions here
4free pages
6concepts
Questions 11–15
- 11
A security analyst is investigating a series of intrusions at a manufacturing company. The analyst discovers that the attackers used a specific remote access tool and a technique for disabling security software. The analyst wants to determine if a known threat actor group is responsible. Which approach using MITRE ATT&CK is most effective?
Select an answer first - 12
Which ATT&CK resource would you use to find a list of software (tools and malware) associated with a specific threat actor group?
Select an answer first - 13
Which ATT&CK tactic is associated with the technique 'Exfiltration Over C2 Channel' (T1041)?
Select an answer first - 14
A security analyst observes a process creating a scheduled task on a Windows host. According to MITRE ATT&CK, what is the most appropriate technique ID for this behavior?
Select an answer first - 15
A regional bank has been notified by a partner that a phishing email was sent to several employees, but the email was blocked before delivery. The bank's security team wants to proactively assess whether the phishing campaign could have led to a significant breach if the email had been delivered. They need to understand the likely end-to-end impact of the campaign. Which approach best aligns with using the MITRE ATT&CK framework to meet this need?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.