Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

CCFH-202 CrowdStrike Certified Falcon Hunter Questions and Answers

Questions 4

What is the main purpose of the Mac Sensor report?

Options:

A.

To identify endpoints that are in Reduced Functionality Mode

B.

To provide a summary view of selected activities on Mac hosts

C.

To provide vulnerability assessment for Mac Operating Systems

D.

To provide a dashboard for Mac related detections

Buy Now
Questions 5

Event Search data is recorded with which time zone?

Options:

A.

PST

B.

GMT

C.

EST

D.

UTC

Buy Now
Questions 6

What kind of activity does a User Search help you investigate?

Options:

A.

A history of Falcon Ul logon activity

B.

A list of process activity executed by the specified user account

C.

A count of failed user logon activity

D.

A list of DNS queries by the specified user account

Buy Now
Questions 7

Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?

Options:

A.

utc_time

B.

conv_time

C.

_time

D.

time

Buy Now
Questions 8

What do you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search?

Options:

A.

PID

B.

Process ID or Parent Process ID

C.

CID

D.

Process Timeline Link

Buy Now
Questions 9

The Falcon Detections page will attempt to decode Encoded PowerShell Command line parameters when which PowerShell Command line parameter is present?

Options:

A.

-Command

B.

-Hidden

C.

-e

D.

-nop

Buy Now
Exam Code: CCFH-202
Exam Name: CrowdStrike Certified Falcon Hunter
Last Update: Nov 21, 2024
Questions: 0
CCFH-202 pdf

CCFH-202 PDF

$28  $80
CCFH-202 Engine

CCFH-202 Testing Engine

$33.25  $95
CCFH-202 PDF + Engine

CCFH-202 PDF + Testing Engine

$297.5  $850