Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CrowdStrike logo

CrowdStrikeCertified Falcon Responder (CCFR)

Domain 1Objective 1

Understand What Information the MITRE ATT&CK Framework Provides CCFR Practice Questions (Page 3)

Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.

28questions here
6free pages
6concepts

Questions 11–15

  1. 11application · medium

    An incident responder is writing a report and needs to describe the adversary's actions in a structured way. They want to include the goal, the method, and the specific tool used. Which ATT&CK elements should they use, respectively?

    Select an answer first
  2. 12application · medium

    A threat intelligence report states that a group used a specific open-source tool to perform credential dumping. In ATT&CK, how would this tool be classified?

    Select an answer first
  3. 13foundation · easy

    What is the role of procedures in the MITRE ATT&CK framework?

    Select an answer first
  4. 14expert · hard

    An incident responder is documenting an attack and needs to decide whether to record the adversary's action as a technique or a procedure. The action is 'used a modified version of Mimikatz to dump credentials'. What is the most appropriate classification?

    Select an answer first
  5. 15application · medium

    A junior analyst asks why the team uses MITRE ATT&CK instead of a simple list of malware signatures. Which response best explains the advantage of ATT&CK?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.