
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 2
Apply MITRE ATT&CK Tactics and Techniques Within Falcon to Provide Context to a Detection CCFR Practice Questions (Page 3)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
23questions here
5free pages
5concepts
Questions 11–15
- 11
A Falcon detection on a workstation shows that a process (winword.exe) spawned a child process (cmd.exe) that ran 'whoami /all'. The detection is mapped to T1033 (System Owner/User Discovery). What is the adversary's PRIMARY goal?
Select an answer first - 12
A security analyst is triaging a Falcon detection and needs to understand the broader context of the attack. The detection is for a PowerShell script that is obfuscated and uses reflection to load a .NET assembly. In Falcon, the analyst sees the detection is mapped to T1059.001 (PowerShell). What additional information should the analyst look for in the 'MITRE ATT&CK' section of the detection details to BEST understand the adversary's goal?
Select an answer first - 13
A security analyst is reviewing a Falcon detection and sees that it is mapped to multiple techniques under the same tactic. The analyst wants to understand the relationship between these techniques. Where in Falcon can the analyst see the full list of techniques and their associated tactics for this detection?
Select an answer first - 14
An analyst is investigating a Falcon detection on a web server. The detection shows that a process (w3wp.exe) made an outbound connection to an IP address on port 443. The detection is mapped to T1071.001 (Web Protocols). The analyst wants to confirm if this is a legitimate connection or a potential C2 channel. Which additional information from the detection details would be MOST helpful?
Select an answer first - 15
How does understanding the ATT&CK tactic of a detection help an analyst?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.