Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CrowdStrike Certified Falcon Responder CCFR-201b Question # 34 Topic 4 Discussion

CrowdStrike Certified Falcon Responder CCFR-201b Question # 34 Topic 4 Discussion

CCFR-201b Exam Topic 4 Question 34 Discussion:
Question #: 34
Topic #: 4

While investigating a detection, you pivot to the Advanced Event Search.

Which field would you filter by to return events executing from a specific directory on the host?


A.

TreeId


B.

@source


C.

ParentBaseFileName


D.

FilePath


Get Premium CCFR-201b Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.