100+ Free ATT&CK Threat Hunting Practice Questions
MITRE ATT&CK Threat Hunting and Detection Engineering (MAD20) practice questions are available now; exam metadata is being verified.
Which technique does an adversary use when they encode malicious PowerShell commands using Base64 to evade signature-based detections?
Explore More MITRE ATT&CK Defender (MAD) Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: ATT&CK Threat Hunting Exam
80%
Passing Score Per Module
MAD20
6 steps
TTP Hunt Methodology Steps
MAD20
Badge-based
Certification Model
MAD20
MITRE Engenuity
Program Origin
MITRE Engenuity / MAD20
Self-paced
Assessment Format
MAD20
ATT&CK Fundamentals
Recommended Prerequisite
MAD20
MITRE Engenuity's MAD20 program teaches and certifies the six-step TTP-based threat hunting methodology: identify adversary behaviors, develop hypotheses, determine data requirements, identify and mitigate gaps, implement and test analytics via purple teaming, and conduct the hunt. The program uses a modular badge model requiring 80% per assessment.
Sample ATT&CK Threat Hunting Practice Questions
Try these sample questions to test your ATT&CK Threat Hunting exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.