
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 1
Understand What Information the MITRE ATT&CK Framework Provides CCFR Practice Questions (Page 1)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
28questions here
6free pages
6concepts
Questions 1–5
- 1
During an incident post-mortem, the team wants to compare the adversary's behavior across two different incidents to see if they are related. How can ATT&CK facilitate this comparison?
Select an answer first - 2
An analyst is documenting an intrusion and notes that the adversary used PowerShell to download and execute a payload. In the ATT&CK matrix, which two elements would this activity be classified under?
Select an answer first - 3
Which statement best describes the source of information used to build the MITRE ATT&CK framework?
Select an answer first - 4
A security team is building detections for a specific threat group. They have access to threat reports that describe the group's use of a custom tool for credential dumping. The team wants to create a detection that is resilient to changes in the tool. Which approach is most aligned with ATT&CK?
Select an answer first - 5
During an investigation, an analyst notes that a specific threat group used a custom PowerShell script to enumerate Active Directory. In ATT&CK terms, what is the custom PowerShell script considered?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.