Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCFH-202 All Questions

View all questions & answers for the CCFH-202 exam

Exam CCFH-202 topic 1 question 38 discussion

Actual exam question from CrowdStrike's CCFH-202
Question #: 38
Topic #: 1
[All CCFH-202 Questions]

What topics are presented in the Hunting and Investigation Guide?

  • A. Detailed tutorial on writing advanced queries such as sub-searches and joins
  • B. Detailed summary of event names, descriptions, and some key data fields for hunting and investigation
  • C. Sample hunting queries, select walkthroughs and best practices for hunting with Falcon
  • D. Recommended platform configurations and prevention settings to ensure detections are generated for hunting leads
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alanalanalan
4 months, 1 week ago
Selected Answer: C
C. Sample hunting queries, select walkthroughs and best practices for hunting with Falcon The Hunting Guide for Windows teaches you how to hunt for adversaries, suspicious activities, suspicious processes, and vulnerabilities on the Windows platform using Falcon. This guide contains information about how to hunt using Falcon and is tailored specifically towards users running the Falcon sensor on Windows devices. However, a lot of the ideas and concepts also apply to users running the Falcon sensor on Mac or Linux. Depending on the sensor platform, however, the names and descriptions of certain events as well as custom query syntax will vary
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...