CrowdStrike Certified Falcon Responder CCFR-201 Question # 17 Topic 2 Discussion

CrowdStrike Certified Falcon Responder CCFR-201 Question # 17 Topic 2 Discussion

CCFR-201 Exam Topic 2 Question 17 Discussion:
Question #: 17
Topic #: 2

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?


A.

ParentProcessld_decimal and aid


B.

ResponsibleProcessld_decimal and aid


C.

ContextProcessld_decimal and aid


D.

TargetProcessld_decimal and aid


Get Premium CCFR-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.