Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFH-202 Topic 7 Question 8 Discussion

Actual exam question for CrowdStrike's CCFH-202 exam
Question #: 8
Topic #: 7
[All CCFH-202 Questions]

Which tool allows a threat hunter to populate and colorize all known adversary techniques in a single view?

Show Suggested Answer Hide Answer
Suggested Answer: D

The Process Timeline Link is what you click to jump to a Process Timeline from many pages in Falcon, such as a Hash Search. The Process Timeline Link is an icon that looks like three horizontal bars with dots on them. It appears next to each process name or ID on various pages in Falcon, such as Hash Search results, Detection details, Event Search results, etc. Clicking on it will open a new tab with the Process Timeline for that process. The PID, the Process ID or Parent Process ID, and the CID are not what you click to jump to a Process Timeline.


Contribute your Thoughts:

Nobuko
2 days ago
I'm not sure, but I think C) OpenXDR could also be a possible answer.
upvoted 0 times
...
Georgiann
9 days ago
I agree with Lonna, MITRE ATT&CK Navigator is the tool that allows threat hunters to view adversary techniques.
upvoted 0 times
...
Micheal
10 days ago
The MITRE ATT&CK Navigator seems like the perfect tool for that! I can't wait to try it out.
upvoted 0 times
...
Lonna
11 days ago
I think the answer is D) MITRE ATT&CK Navigator.
upvoted 0 times
...

Save Cancel