Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCFR-201 All Questions

View all questions & answers for the CCFR-201 exam

Exam CCFR-201 topic 1 question 54 discussion

Actual exam question from CrowdStrike's CCFR-201
Question #: 54
Topic #: 1
[All CCFR-201 Questions]

What does pivoting to an Event Search from a detection do?

  • A. It gives you the ability to search for similar events on other endpoints quickly
  • B. It takes you to the raw Insight event data and provides you with a number of Event Actions
  • C. It takes you to a Process Timeline for that detection so you can see all related events
  • D. It allows you to input an event type, such as DNS Request or ASEP write, and search for those events within the detection
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alanalanalan
6 months ago
Selected Answer: B
Answer agree with B
upvoted 1 times
...
jdilliway
9 months, 3 weeks ago
Selected Answer: B
Agreed with sbag0024. The correct answer is 'B'. When investigating a detection, there will be a magnifying glass icon. Hovering and selecting 'Event Search' will open the Splunk equivalent search engine, exposing all of the raw data from the 'aid' and 'treeIdDecimal'.
upvoted 1 times
...
sbag0024
9 months, 3 weeks ago
Selected Answer: B
The answer is B. When you click on Full Detection data and then the 3 dots, you can pivot to Event Seach where you land on the raw data info where you can select "Event Actions" which there are a number of them to select. Going with B
upvoted 3 times
...
wildbandana
11 months, 2 weeks ago
Selected Answer: D
right one is D
upvoted 1 times
jdilliway
9 months, 3 weeks ago
You're wrong. It's B.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...