
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 1Objective 2
1.2 Utilize the MITRE ATT&CK Framework to Model Threat Actor Behaviors CCFH Practice Questions (Page 3)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
25questions here
5free pages
4concepts
Questions 11–15
- 11
How can a security team use MITRE ATT&CK mappings to improve their detection strategy?
Select an answer first - 12
A security team is investigating a sophisticated attack that involved both IT and OT environments. The attacker used a spear-phishing email to gain initial access to the IT network, then moved laterally to the OT network and manipulated a safety controller. The team needs to document the full attack chain. Which combination of matrices should they use?
Select an answer first - 13
A detection engineering team is building alerts for a known threat group that commonly uses scheduled tasks for persistence and PowerShell for execution. The team wants to ensure they have coverage for the entire attack chain. Which approach best utilizes ATT&CK to achieve this?
Select an answer first - 14
A threat hunter observes an adversary using PowerShell to download and execute a script from a remote server. According to MITRE ATT&CK, which tactic is the adversary most directly achieving?
Select an answer first - 15
During incident response, how can MITRE ATT&CK be used to prioritize actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.