
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 1Objective 2
1.2 Utilize the MITRE ATT&CK Framework to Model Threat Actor Behaviors CCFH Practice Questions (Page 2)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
25questions here
5free pages
4concepts
Questions 6–10
- 6
Which of the following correctly describes the structure of the MITRE ATT&CK framework?
Select an answer first - 7
A security analyst is analyzing a malware sample that targets point-of-sale (POS) systems and is designed to scrape credit card data from memory. The analyst needs to map this to the appropriate ATT&CK matrix. Which matrix and technique should they use?
Select an answer first - 8
A threat hunting team is reviewing a recent intrusion where the attacker used a spear-phishing email to deliver a malicious macro, which then established persistence via a scheduled task and later used RDP for lateral movement. The team wants to prioritize detection improvements. Based on the ATT&CK mapping, which tactic should the team focus on first to detect the initial compromise?
Select an answer first - 9
In the MITRE ATT&CK framework, what is the relationship between tactics and techniques?
Select an answer first - 10
An analyst is documenting a threat actor's use of a legitimate cloud storage service to exfiltrate data. The analyst needs to map this to ATT&CK. Which technique and tactic pair is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.