
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 2
Apply MITRE ATT&CK Tactics and Techniques Within Falcon to Provide Context to a Detection CCFR Practice Questions (Page 4)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
23questions here
5free pages
5concepts
Questions 16–20
- 16
An analyst is investigating a Falcon detection on a file server. The detection shows that a process (powershell.exe) is running a script that is using the .NET WebClient class to download a file from a remote server and save it to a local share. The detection is mapped to T1105 (Ingress Tool Transfer). The analyst needs to determine the MOST likely impact of this technique on the file server. Which additional ATT&CK context is MOST relevant?
Select an answer first - 17
A Falcon detection indicates that a process is sending large volumes of data to an external IP address. Which ATT&CK tactic is most directly indicated?
Select an answer first - 18
What is the primary purpose of the MITRE ATT&CK framework?
Select an answer first - 19
A Falcon detection shows that a process attempted to disable a security tool on an endpoint. Which MITRE ATT&CK tactic best describes the adversary's goal?
Select an answer first - 20
A Falcon detection shows a process using PowerShell to download and execute a payload from a remote server. Which ATT&CK technique is most directly indicated?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.