
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 2
Apply MITRE ATT&CK Tactics and Techniques Within Falcon to Provide Context to a Detection CCFR Practice Questions (Page 1)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
23questions here
5free pages
5concepts
Questions 1–5
- 1
An analyst is investigating a Falcon detection on a critical server. The detection shows a process (svchost.exe) creating a new service with a random name. The detection is mapped to T1543.003 (Windows Service). The analyst needs to determine the MOST likely impact of this technique on the server's availability. Which additional ATT&CK context is MOST relevant to assess this impact?
Select an answer first - 2
A Falcon detection on a user's workstation shows that a process (powershell.exe) is running a script that is using the Invoke-WebRequest cmdlet to download a file from a remote server and save it to the user's Downloads folder. The detection is mapped to T1105 (Ingress Tool Transfer). What is the adversary's PRIMARY goal?
Select an answer first - 3
When investigating a detection in Falcon, what does the 'ATT&CK' field in the detection details typically show?
Select an answer first - 4
An analyst is investigating a Falcon detection on a web server. The detection shows that a process spawned a child process that ran 'whoami', 'net user', and 'ipconfig' in quick succession. In Falcon, the analyst navigates to the detection details and sees a 'Technique' field populated with 'T1033' (System Owner/User Discovery). Which ATT&CK tactic is this technique most directly associated with?
Select an answer first - 5
A Falcon detection is mapped to the 'Lateral Movement' tactic. What does this context suggest about the potential impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.