exam questions

Exam CCFH-202 All Questions

View all questions & answers for the CCFH-202 exam

Exam CCFH-202 topic 1 question 84 discussion

Actual exam question from CrowdStrike's CCFH-202
Question #: 84
Topic #: 1
[All CCFH-202 Questions]

You initiate a search with the following query:

event_simpleName=UserLogon | table _time ComputerName UserName

What results will display?

  • A. Machine-readable event host time, host name, user name
  • B. Human-readable event host time, host name, user name
  • C. Machine-readable event cloud time, host name, user name
  • D. Human-readable event cloud time, host name, user name
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
joal23
Highly Voted 1 year, 4 months ago
The correct is letter D, because the query has the fields "_time", "ComputerName" and "UserName". And the field "_time" means timestamp of the moment that the event was received by the Crowdstrike cloud ont Event Data Dictionary document. You can run the query "event_simpleName=UserLogon | table _time ComputerName UserName" on event search and see the results.
upvoted 7 times
...
Amulet9735
Most Recent 1 month, 1 week ago
Selected Answer: D
From the Event Data Dictionary: "_time: Timestamp of the moment that the event was received by the CrowdStrike cloud. This is not to be confused with the time the event was generated locally on the system. This is the timestamp Of the event from the clouds point Of view. This value can be converted to any time format and can be used for calculations." Lots of references to the cloud time in there.
upvoted 1 times
...
alanalanalan
7 months, 1 week ago
Selected Answer: B
B. Human-readable event host time, host name, user name Falcon Documentation > Event Investigation > Events > About Events _time Timestamp of the moment that the event was received by the CrowdStrike cloud. This is not to be confused with the time the event was generated locally on the system. This is the timestamp of the event from the cloud's point of view. This value can be converted to any time format and can be used for calculations. "10/19/2017 18:10:29.396"
upvoted 1 times
NastyNutsu
2 months ago
Based on this information, shouldn't the answer be D then?
upvoted 1 times
...
...
Tech_Amit
10 months, 4 weeks ago
Correct answer is A : Machine-readable event host time, host name, user name Reference : _time : The host's local time in epoch format."1538648887.051" https://falcon.crowdstrike.com/documentation/page/e3ce0b24/events-data-dictionary
upvoted 1 times
...
kangaru
1 year, 1 month ago
Selected Answer: D
Event Host Time is identified through ContextTimeStamp_decimal instead.
upvoted 1 times
...
gr23
1 year, 1 month ago
D _time is the command to covert cloud event time from EPOC to UTC readable.
upvoted 2 times
...
Acrby
1 year, 2 months ago
Selected Answer: B
event host time” and “event cloud time” are two different timestamps that are used to track when an event occurred on the host and when it was ingested into the cloud-based logging service, respectively
upvoted 1 times
...
examtopics3000
1 year, 7 months ago
Selected Answer: B
I think the correct answer is B. If I run that query it is human readable.
upvoted 3 times
...
examtopics3000
1 year, 7 months ago
I think the correct answer is B.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago