Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 1Objective 2

1.2 Utilize the MITRE ATT&CK Framework to Model Threat Actor Behaviors CCFH Practice Questions (Page 2)

Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.

25questions here
5free pages
4concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following correctly describes the structure of the MITRE ATT&CK framework?

    Select an answer first
  2. 7application · medium

    A security analyst is analyzing a malware sample that targets point-of-sale (POS) systems and is designed to scrape credit card data from memory. The analyst needs to map this to the appropriate ATT&CK matrix. Which matrix and technique should they use?

    Select an answer first
  3. 8application · medium

    A threat hunting team is reviewing a recent intrusion where the attacker used a spear-phishing email to deliver a malicious macro, which then established persistence via a scheduled task and later used RDP for lateral movement. The team wants to prioritize detection improvements. Based on the ATT&CK mapping, which tactic should the team focus on first to detect the initial compromise?

    Select an answer first
  4. 9foundation · easy

    In the MITRE ATT&CK framework, what is the relationship between tactics and techniques?

    Select an answer first
  5. 10application · medium

    An analyst is documenting a threat actor's use of a legitimate cloud storage service to exfiltrate data. The analyst needs to map this to ATT&CK. Which technique and tactic pair is correct?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.