CCFH-202 Exam Question 26

You are reviewing a list of domains recently banned by your organization's acceptable use policy. In particular, you are looking for the number of hosts that have visited each domain. Which tool should you use in Falcon?
  • CCFH-202 Exam Question 27

    Refer to Exhibit.

    Falcon detected the above file attempting to execute. At initial glance; what indicators can we use to provide an initial analysis of the file?
  • CCFH-202 Exam Question 28

    In which of the following stages of the Cyber Kill Chain does the actor not interact with the victim endpoint(s)?
  • CCFH-202 Exam Question 29

    Which of the following is a suspicious process behavior?
  • CCFH-202 Exam Question 30

    The Falcon Detections page will attempt to decode Encoded PowerShell Command line parameters when which PowerShell Command line parameter is present?