Loading provider exams...
Sign Up & unlock 100% of Exam Questions
No Strings Attached!
Updated
When reviewing a Host Timeline, which of the following filters is available?
This exam has 60 community-verified practice questions. Create a free account to access all questions, comments, and explanations.
From a detection, what is the fastest way to see children and sibling process information?
Which of the following is NOT a filter available on the Detections page?
What are Event Actions?
Which is TRUE regarding a file released from quarantine?
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Where can you find hosts that are in Reduced Functionality Mode?
How does a DNSRequest event link to its responsible process?
What is an advantage of using a Process Timeline?
The Bulk Domain Search tool contains Domain information along with which of the following?
Where are quarantined files stored on Windows hosts?
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
The function of Machine Learning Exclusions is to _____________.
What information does the MITRE ATT&CK Framework provide?
Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
How long does detection data remain in the CrowdStrike Cloud before purging begins?
What action is used when you want to save a prevention hash for later use?
You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?
In the Hash Search tool, which of the following is listed under Process Executions?
What is the difference between a Host Search and a Host Timeline?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
What is an advantage of using the IP Search tool?
What happens when you open the full detection details?