Question 6 of 91

What is the purpose of this query?
Exam ccfh-202b: Image 1
Answer

Suggested Answer

The suggested answer is D.

Question 7 of 91

Refer to the image.
Exam CCFH-202b: Image 1
Why are there six pending containment events?
Answer

Suggested Answer

The suggested answer is B.

Question 8 of 91

Falcon is generating detections for a malicious file evil.exe with varying filepaths on several hosts as end users attempt to execute the file.
Which query can be used to proactively hunt where the file exists prior to the user executing it?
Answer

Suggested Answer

The suggested answer is A.

Question 9 of 91

Which CQL query would output relevant data in tracking USB storage device usage?
Answer

Suggested Answer

The suggested answer is C.

Question 10 of 91

During an investigation you suspect that wget is used broadly to pull commands from C2 servers with public IP addresses.
How can you generate an overview of all those addresses?
Answer

Suggested Answer

The suggested answer is C.