Agreed with sbag0024. The correct answer is 'B'. When investigating a detection, there will be a magnifying glass icon. Hovering and selecting 'Event Search' will open the Splunk equivalent search engine, exposing all of the raw data from the 'aid' and 'treeIdDecimal'.
The answer is B. When you click on Full Detection data and then the 3 dots, you can pivot to Event Seach where you land on the raw data info where you can select "Event Actions" which there are a number of them to select. Going with B
This section is not available anymore. Please use the main Exam Page.CCFR-201 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alanalanalan
5 months agojdilliway
8 months, 3 weeks agosbag0024
8 months, 4 weeks agowildbandana
10 months, 2 weeks agojdilliway
8 months, 3 weeks ago