You have found a hash-based indicator of compromise (IOC) in an intelligence report and want to determine if the program has run in your environment. Which search would provide all of the process’ executions over the timeframe specified?
If you have a hash-based indicator of compromise (IOC) and want to determine if the corresponding program has executed in your environment, searching by hash is the most direct and effective method.
This section is not available anymore. Please use the main Exam Page.CCFH-202 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
NastyNutsu
3 months, 3 weeks agoalanalanalan
9 months ago[Removed]
10 months, 3 weeks agoTech_Amit
1 year agogr23
1 year, 3 months agoSunaperi
1 year, 5 months ago