Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFH-202b Exam - Topic 1 Question 6 Discussion

Actual exam question for CrowdStrike's CCFH-202b exam
Question #: 6
Topic #: 1
[All CCFH-202b Questions]

Which of the following queries will return the parent processes responsible for launching badprogram exe?

Show Suggested Answer Hide Answer
Suggested Answer: D

This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.


Contribute your Thoughts:

0/2000 characters
Tandra
4 days ago
I agree with C, it makes the most sense.
upvoted 0 times
...
Annamae
9 days ago
Wait, is "badprogranrexe" a typo in A?
upvoted 0 times
...
Frederic
14 days ago
I think D is the correct one, actually.
upvoted 0 times
...
Merlyn
20 days ago
Option C looks right to me.
upvoted 0 times
...
Tayna
25 days ago
I have a feeling that option D is the one we discussed in class, but I’m not entirely confident about the field names used.
upvoted 0 times
...
Margart
30 days ago
I’m a bit confused about the difference between options B and D; they both seem to involve renaming fields, but I can't recall which one is more accurate.
upvoted 0 times
...
Rana
1 month ago
I remember practicing with similar queries, and I feel like option C might be the right approach since it directly mentions ParentProcessName.
upvoted 0 times
...
Loren
1 month ago
I think option A looks familiar, but I’m not sure if it correctly references the parent processes.
upvoted 0 times
...

Save Cancel