CrowdStrike Certified Falcon Hunter CCFH-202 Question # 3 Topic 1 Discussion

CrowdStrike Certified Falcon Hunter CCFH-202 Question # 3 Topic 1 Discussion

CCFH-202 Exam Topic 1 Question 3 Discussion:
Question #: 3
Topic #: 1

Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes?


A.

Real Time Response and Network Containment


B.

Hunting and Investigation


C.

Events Data Dictionary


D.

Incident and Detection Monitoring


Get Premium CCFH-202 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.