CCFH-202 Exam Question 21

Which of the following best describes the purpose of the Mac Sensor report?
  • CCFH-202 Exam Question 22

    You want to produce a list of all event occurrences along with selected fields such as the full path, time, username etc. Which command would be the appropriate choice?
  • CCFH-202 Exam Question 23

    Which pre-defined reports offer information surrounding activities that typically indicate suspicious activity occurring on a system?
  • CCFH-202 Exam Question 24

    Which Falcon documentation guide should you reference to hunt for anomalies related to scheduled tasks and other Windows related artifacts?
  • CCFH-202 Exam Question 25

    You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?