Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CrowdStrike Certified Falcon Hunter CCFH-202b Question # 18 Topic 2 Discussion

CrowdStrike Certified Falcon Hunter CCFH-202b Question # 18 Topic 2 Discussion

CCFH-202b Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

You've experienced a ransomware infection that has spread throughout the enterprise. What is the first step you would take to determine the source of infection?


A.

Perform a PowerShell hunt to look for suspicious PowerShell commands


B.

Use Advanced Event Search to timeline encryption activity and determine the system with the first encryption event


C.

Utilize Exposure Management to identify systems with critical vulnerabilities that could be exploited


D.

Perform reverse engineering on the malware sample to see if you can find the infection vector


Get Premium CCFH-202b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.