
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 1
Understand What Information the MITRE ATT&CK Framework Provides CCFR Practice Questions (Page 5)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
28questions here
6free pages
6concepts
Questions 21–25
- 21
During a security review, a manager asks the incident response team to justify their use of MITRE ATT&CK. The team has been mapping observed adversary actions to ATT&CK techniques. Which statement best explains the primary value of using ATT&CK in this context?
Select an answer first - 22
How can the MITRE ATT&CK framework be used to improve detection capabilities in incident response?
Select an answer first - 23
During an incident review, the team categorizes adversary actions into columns on the ATT&CK matrix. One column is labeled 'Persistence'. What does this column represent in the context of the framework?
Select an answer first - 24
In the ATT&CK matrix, the columns represent tactics. Which of the following is a tactic, not a technique or procedure?
Select an answer first - 25
During an incident investigation, the team discovers that the adversary used a technique that is not yet documented in ATT&CK. What should the team do to ensure their findings are still useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.