
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 1Objective 2
1.2 Utilize the MITRE ATT&CK Framework to Model Threat Actor Behaviors CCFH Practice Questions (Page 1)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
25questions here
5free pages
4concepts
Questions 1–5
- 1
A detection engineering team is reviewing a threat actor's TTPs and wants to create a detection that covers multiple techniques with a single rule. The actor uses scheduled tasks for persistence and also uses scheduled tasks to execute malicious code. Which ATT&CK technique should the team focus on to create a single detection?
Select an answer first - 2
A security analyst is reviewing an alert where an attacker used a USB drive to deliver malware to a workstation. The analyst needs to document this in ATT&CK. Which technique and tactic should be recorded?
Select an answer first - 3
A security team is analyzing a mobile malware sample that abuses accessibility services to steal credentials from banking apps. The team needs to map this behavior to the appropriate ATT&CK matrix. Which matrix and tactic should they use?
Select an answer first - 4
During a threat hunt, an analyst finds that an attacker created a new local user account and added it to the local administrators group. The analyst needs to map this to ATT&CK. Which tactic and technique pair is correct?
Select an answer first - 5
A security analyst is investigating a suspected intrusion into an industrial control system (ICS) environment. The analyst observes that an attacker modified ladder logic on a programmable logic controller (PLC) to cause a physical process to operate unsafely. The analyst needs to document this behavior using the MITRE ATT&CK framework. Which matrix and tactic should the analyst reference?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.