
CrowdStrikeCertified Falcon Responder (CCFR)
Domain 1Objective 1
Understand What Information the MITRE ATT&CK Framework Provides CCFR Practice Questions (Page 6)
Part of the ATT&CK Frameworks domain, which makes up ~10% of our current practice bank.
28questions here
6free pages
6concepts
Questions 26–28
- 26
Which of the following is a common tactic category in the MITRE ATT&CK framework?
Select an answer first - 27
A security team wants to evaluate their detection coverage against known adversary behavior. They have a list of techniques used by a specific threat group. How can MITRE ATT&CK help them identify gaps in their detection capabilities?
Select an answer first - 28
An analyst is reviewing ATT&CK documentation and sees that 'T1059.001' refers to 'PowerShell'. What does the '.001' suffix indicate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCFR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFR” is a trademark of its owner, used for identification only.