CCFH-202 Exam Question 16
What is the difference between a Host Search and a Host Timeline?
CCFH-202 Exam Question 17
Refer to Exhibit.

What type of attack would this process tree indicate?

What type of attack would this process tree indicate?
CCFH-202 Exam Question 18
Which of the following is a recommended technique to find unique outliers among a set of data in the Falcon Event Search?
CCFH-202 Exam Question 19
What Search page would help a threat hunter differentiate testing, DevOPs, or general user activity from adversary behavior?
CCFH-202 Exam Question 20
Where would an analyst find information about shells spawned by root, Kernel Module loads, and wget/curl usage?
