CrowdStrike Certified Falcon Hunter CCFH-202 Question # 7 Topic 1 Discussion

CrowdStrike Certified Falcon Hunter CCFH-202 Question # 7 Topic 1 Discussion

CCFH-202 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

Which field should you reference in order to find the system time of a *FileWritten event?


A.

ContextTimeStamp_decimal


B.

FileTimeStamp_decimal


C.

ProcessStartTime_decimal


D.

timestamp


Get Premium CCFH-202 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.