CCFH-202 Exam QuestionsBrowse all questions from this exam

CCFH-202 Exam - Question 84


You initiate a search with the following query:

event_simpleName=UserLogon | table _time ComputerName UserName

What results will display?

Show Answer
Correct Answer: B

The query contains the fields '_time', 'ComputerName', and 'UserName'. The '_time' field in this context represents the timestamp of the event which is displayed in a human-readable format by default in most query tools, including Splunk. Therefore, the results will display human-readable event time, host name, and user name.

Discussion

9 comments
Sign in to comment
joal23
Oct 20, 2023

The correct is letter D, because the query has the fields "_time", "ComputerName" and "UserName". And the field "_time" means timestamp of the moment that the event was received by the Crowdstrike cloud ont Event Data Dictionary document. You can run the query "event_simpleName=UserLogon | table _time ComputerName UserName" on event search and see the results.

examtopics3000Option: B
Aug 3, 2023

I think the correct answer is B. If I run that query it is human readable.

examtopics3000
Aug 3, 2023

I think the correct answer is B.

gr23
Jan 11, 2024

D _time is the command to covert cloud event time from EPOC to UTC readable.

AcrbyOption: B
Dec 13, 2023

event host time” and “event cloud time” are two different timestamps that are used to track when an event occurred on the host and when it was ingested into the cloud-based logging service, respectively

kangaruOption: D
Jan 14, 2024

Event Host Time is identified through ContextTimeStamp_decimal instead.

Tech_Amit
Apr 14, 2024

Correct answer is A : Machine-readable event host time, host name, user name Reference : _time : The host's local time in epoch format."1538648887.051" https://falcon.crowdstrike.com/documentation/page/e3ce0b24/events-data-dictionary

alanalanalanOption: B
Jul 28, 2024

B. Human-readable event host time, host name, user name Falcon Documentation > Event Investigation > Events > About Events _time Timestamp of the moment that the event was received by the CrowdStrike cloud. This is not to be confused with the time the event was generated locally on the system. This is the timestamp of the event from the cloud's point of view. This value can be converted to any time format and can be used for calculations. "10/19/2017 18:10:29.396"

NastyNutsu
Jan 2, 2025

Based on this information, shouldn't the answer be D then?

Amulet9735Option: D
Jan 30, 2025

From the Event Data Dictionary: "_time: Timestamp of the moment that the event was received by the CrowdStrike cloud. This is not to be confused with the time the event was generated locally on the system. This is the timestamp Of the event from the clouds point Of view. This value can be converted to any time format and can be used for calculations." Lots of references to the cloud time in there.