Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 1Objective 2

Apply MITRE ATT&CK Tactics and Techniques Within Falcon to Provide Context to a Detection CCFR Practice Questions (Page 2)

Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.

23questions here
5free pages
5concepts

Questions 6–10

  1. 6foundation · easy

    In the MITRE ATT&CK framework, what do 'procedures' (the 'P' in TTPs) describe?

    Select an answer first
  2. 7application · medium

    A Falcon detection on a domain controller shows a process (lsass.exe) being accessed by a suspicious tool. The detection is mapped to technique T1003.001 (LSASS Memory). What is the adversary's PRIMARY goal based on this technique?

    Select an answer first
  3. 8application · medium

    A Falcon detection on a user's workstation shows that a process (explorer.exe) spawned a child process (cmd.exe) that ran 'reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d C:\Users\Public\update.exe'. The detection is mapped to T1547.001 (Registry Run Keys / Startup Folder). What is the adversary's PRIMARY goal?

    Select an answer first
  4. 9application · medium

    An analyst is investigating a Falcon detection that shows a process (cmd.exe) creating a scheduled task. The detection is mapped to technique T1053.005 (Scheduled Task). The analyst wants to determine the most likely 'next step' in the attack chain based on this technique. Which question is the MOST useful to answer to apply the ATT&CK context?

    Select an answer first
  5. 10foundation · easy

    In the Falcon console, where can you typically view the MITRE ATT&CK tactic and technique information associated with a specific detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.