QuestionQ46

Findings and Detection Analysis

You are investigating possible data exfiltration by reviewing IOAs in Falcon Cloud Security. You need to check for evidence of Ransomware activity on EC2 instances.

Which IOA filters satisfy these requirements for identifying related IOAs?

  • A MITRE Tactic and Technique -Service
  • B Attack type -Cloud provider
  • C MITRE Tactic and Technique -Cloud provider
  • D Attack type -Service
Explanation

The Attack type filter identifies ransomware-related activity, while the Service filter scopes results to the relevant cloud service, Amazon EC2. Together, they identify ransomware IOAs associated with EC2 instances.

Community Discussion

No comments yet. Be the first to start the discussion!