CCFH-202 Exam Question 1

Refer to Exhibit.

Falcon detected the above file attempting to execute. At initial glance; what indicators can we use to provide an initial analysis of the file?
  • CCFH-202 Exam Question 2

    What is the main purpose of the Mac Sensor report?
  • CCFH-202 Exam Question 3

    Adversaries commonly execute discovery commands such as netexe, ipconfig.exe, and whoami exe. Rather than query for each of these commands individually, you would like to use a single query with all of them. What Splunk operator is needed to complete the following query?
  • CCFH-202 Exam Question 4

    What topics are presented in the Hunting and Investigation Guide?
  • CCFH-202 Exam Question 5

    What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?