Exam CCFH-202 All QuestionsBrowse all questions from this exam
Question 52

When reviewing a DNS request in the Event Search, you're curious which process made the request. Which Event Action would be the quickest way to show you the process?

    Correct Answer: C

Discussion
kangaruOption: C

event_simpleName=DnsRequest is a process that is spawned by a TargetProcessId that is 'event_simpleName=ProcessRollup2'. It doesn't have a ParentProcessId in the field hence B is wrong. C is correct because by clicking 'Show Responsible Process Data', it automatically pivots the event's ContextProcessId as the TargetProcessId to find its 'spawner'.

SunaperiOption: A

should be A