Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 1Objective 2

Apply MITRE ATT&CK Tactics and Techniques Within Falcon to Provide Context to a Detection CCFR Practice Questions (Page 5)

Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.

23questions here
5free pages
5concepts

Questions 21–23

  1. 21foundation · easy

    A Falcon detection shows that a process created a scheduled task to run a script. Which ATT&CK technique is most directly associated with this behavior?

    Select an answer first
  2. 22application · medium

    An analyst is investigating a Falcon detection on a workstation. The detection shows that a process (cmd.exe) is running 'net user /add hacker P@ssw0rd'. The detection is mapped to T1136.001 (Local Account). What is the adversary's PRIMARY goal?

    Select an answer first
  3. 23application · easy

    A junior analyst is reviewing a Falcon detection and needs to quickly understand the adversary's overall objective and how this detection fits into a larger attack chain. Where in the Falcon console should the analyst look to find the ATT&CK tactic and technique information linked to this specific detection?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCFR

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.