
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 1
Understand What Information the MITRE ATT&CK Framework Provides CCFR Practice Questions (Page 3)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
28questions here
6free pages
6concepts
Questions 11–15
- 11
An incident responder is writing a report and needs to describe the adversary's actions in a structured way. They want to include the goal, the method, and the specific tool used. Which ATT&CK elements should they use, respectively?
Select an answer first - 12
A threat intelligence report states that a group used a specific open-source tool to perform credential dumping. In ATT&CK, how would this tool be classified?
Select an answer first - 13
What is the role of procedures in the MITRE ATT&CK framework?
Select an answer first - 14
An incident responder is documenting an attack and needs to decide whether to record the adversary's action as a technique or a procedure. The action is 'used a modified version of Mimikatz to dump credentials'. What is the most appropriate classification?
Select an answer first - 15
A junior analyst asks why the team uses MITRE ATT&CK instead of a simple list of malware signatures. Which response best explains the advantage of ATT&CK?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.