When performing a raw event search via the Events search page, what are Event Actions?
A.
Event Actions contains an audit information log of actions an analyst took in regards to a specific detection.
B.
Event Actions contains the summary of actions taken by the Falcon sensor such as quarantining a file, prevent a process from executing or taking no actions and creating a detection only.
C.
Event Actions are pivotable workflows including connecting to a host, pre-made event searches and pivots to other investigatory pages such as host search.
D.
Event Actions is the field name that contains the event name defined in the Events Data Dictionary such as ProcessRollup, SyntheticProcessRollup, DNS request, etc.
C
C. Event Actions are pivotable workflows including connecting to a host, pre-made event searches and pivots to other investigatory pages such as host search.
When performing a raw event search via the Events search page, Event Actions are pivotable
workflows that allow you to perform various tasks related to the event or the host.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alanalanalan
3 months, 4 weeks agogr23
10 months, 2 weeks agoVasiOnCacao
11 months agoChiquitabandita
1 year, 2 months ago