Exam CCFH-202 All QuestionsBrowse all questions from this exam
Question 40

Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes?

    Correct Answer: B

    The document that provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes is 'Hunting and Investigation'. This document focuses specifically on the activities involved in hunting and investigating suspicious activities.

Discussion
alanalanalanOption: B

B. Hunting and Investigation question keyword "hunt"