CCFH-202 Exam Question 11

In the Powershell Hunt report, what does the "score" signify?
  • CCFH-202 Exam Question 12

    Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes?
  • CCFH-202 Exam Question 13

    You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?
  • CCFH-202 Exam Question 14

    Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?
  • CCFH-202 Exam Question 15

    In the MITRE ATT&CK Framework (version 11 - the newest version released in April 2022), which of the following pair of tactics is not in the Enterprise: Windows matrix?