Which of the following tactic and technique combinations is sourced from MITRE ATT&CK information?
What do IOA exclusions help you achieve?
How does a DNSRequest event link to its responsible process?
You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
What does the Full Detection Details option provide?
When looking at the details of a detection, there are two fields called Global Prevalence and Local Prevalence. Which answer best defines Local Prevalence?
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
From the Detections page, how can you view 'in-progress' detections assigned to Falcon Analyst Alex?
What is an advantage of using the IP Search tool?
You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
How long are quarantined files stored in the CrowdStrike Cloud?
Which is TRUE regarding a file released from quarantine?
When you configure and apply an IOA exclusion, what impact does it have on the host and what you see in the console?
From a detection, what is the fastest way to see children and sibling process information?
How are processes on the same plane ordered (bottom 'VMTOOLSD.EXE' to top CMD.EXE')?
Which of the following is returned from the IP Search tool?