Exam CCFR-201 All QuestionsBrowse all questions from this exam
Question 5

Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?

    Correct Answer: A

    An adversary is trying to keep access through persistence by creating an account. Within the MITRE-Based Falcon Detections Framework, the tactic of 'Keep Access' is associated with techniques that adversaries use to maintain their foothold in a system. 'Persistence' includes various methods used by adversaries to ensure they can maintain access to a system across reboots, credential changes, and other interruptions that could cut off their access. 'Create Account' is a specific technique where an adversary creates a new account on the system to ensure they can regain access even if their initial method of entry is discovered and blocked. Thus, the correct way to interpret 'Keep Access > Persistence > Create Account' is that an adversary is trying to keep access through persistence by creating an account.

Discussion
lightmagentaOption: A

correct answer is A

sbag0024Option: A

Going with A on this one. Per https://attack.mitre.org/techniques/T1136/ . "Adversaries may create an account to maintain access to victim systems."