Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Hunter (CCFH)

Domain 1Objective 2

1.2 Utilize the MITRE ATT&CK Framework to Model Threat Actor Behaviors CCFH Practice Questions (Page 4)

Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.

25questions here
5free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A security analyst is reviewing an alert where an attacker used a legitimate system tool (e.g., PowerShell) to perform actions that are also commonly performed by administrators. The analyst needs to determine if this is malicious or benign. Which approach best uses ATT&CK to make this determination?

    Select an answer first
  2. 17foundation · easy

    In the MITRE ATT&CK enterprise matrix, what is the relationship between a technique and its sub-techniques?

    Select an answer first
  3. 18foundation · easy

    An analyst sees an alert for a process creating a scheduled task on a Windows host. Which MITRE ATT&CK tactic is the adversary most likely pursuing?

    Select an answer first
  4. 19application · medium

    A threat hunting team is reviewing a series of alerts and wants to identify which techniques are not currently covered by their detection stack. They have mapped all observed behaviors to ATT&CK. Which approach best uses ATT&CK to identify coverage gaps?

    Select an answer first
  5. 20application · medium

    An analyst is documenting a threat actor's behavior: the actor used a legitimate Windows tool (PsExec) to execute commands remotely on multiple hosts. The analyst needs to classify this activity in ATT&CK. Which technique and tactic pair is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.