
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 6Objective 2
6.2 Understand Target Systems (asset Inventory and Who Would Target Those Assets) CCFH Practice Questions (Page 4)
Part of the Hunting Analytics domain, which makes up ~25% of our current practice bank.
25questions here
5free pages
5concepts
Questions 16–20
- 16
A government contractor has two assets: a system with classified military designs and a system with unclassified but sensitive procurement data. The security team has detected an intrusion that appears to be from a nation-state. The attackers have accessed the procurement system but not the classified system. Which hunting hypothesis is most likely?
Select an answer first - 17
A threat hunter observes a nation-state actor known for intellectual property theft. Which asset type would be the most logical focus for hunting hypotheses?
Select an answer first - 18
A hospital is updating its asset inventory. They have a patient portal, an imaging system (PACS), and a building management system (BMS) that controls HVAC. The security team must prioritize hunting for a ransomware attack. Which asset is most likely to be targeted to maximize operational disruption?
Select an answer first - 19
Which of the following best represents the full scope of assets that constitute an organization's attack surface?
Select an answer first - 20
A media company has a video streaming platform and an internal system that stores unreleased film content. The security team has detected an intrusion that exfiltrated a large amount of data from the unreleased content system. The attackers did not target the streaming platform. Which threat actor profile is most likely?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.