You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
What happens when a hash is allowlisted?
Which of the following is returned from the IP Search tool?
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
The function of Machine Learning Exclusions is to___________.
The Process Activity View provides a rows-and-columns style view of the events generated in a detection. Why might this be helpful?
PDF + Testing Engine
|
---|
$66 |
Testing Engine
|
---|
$50 |
PDF (Q&A)
|
---|
$42 |
CrowdStrike Free Exams |
---|
![]() |