CCFR-201 Exam QuestionsBrowse all questions from this exam

CCFR-201 Exam - Question 26


When examining a raw DNS request event, you see a field called ContextProcessId_decimal. What is the purpose of that field?

Show Answer
Correct Answer: C

The ContextProcessId_decimal field represents the ContextProcessId decimal value for the parent process that made the DNS request. This means it identifies the process that initiated the DNS request, which is useful information when analyzing raw DNS request events. Knowing the parent process can help in tracing back the origin of the request and understanding the sequence of processes involved.

Discussion

4 comments
Sign in to comment
wildbandanaOption: D
Dec 14, 2023

I think is D

VasiOnCacaoOption: D
Dec 22, 2023

Actually, here I also think it might be D. Look at this reddit post - https://www.reddit.com/r/crowdstrike/comments/hr1kyb/rename_contextprocessid_decimal_as/. In other words ContextProcessId is generated to enrich the TargetProcessId event and has the same value. The main event won't contain ContextProcessId event, but a TargetProcessId.

sbag0024
Jan 31, 2024

Not sure about D for this one it says TargetProcessID. NOT TargetProcessId_decimal. Both TargetProcessId and TargetProcessId_decimal are different things. I don't see a correct answer here?

sbag0024
Jan 31, 2024

Actually might be C.

sbag0024
Jan 31, 2024

Not sure on this one.

kangaruOption: D
Feb 11, 2024

ContextProcessId of DnsRequest event is equal to the TargetProcessId of the event that spawned the DnsRequest event.

alanalanalanOption: D
May 21, 2024

agree with D