CrowdStrike CCFR-201 - CrowdStrike Certified Falcon Responder
What is an advantage of using a Process Timeline?
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
How long does detection data remain in the CrowdStrike Cloud before purging begins?
You are notified by a third-party that a program may have redirected traffic to a malicious domain. Which Falcon page will assist you in searching for any domain request information related to this notice?
Which Executive Summary dashboard item indicates sensors running with unsupported versions?
You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
How long are quarantined files stored on the host?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?