Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFR-201 Topic 1 Question 14 Discussion

Actual exam question for CrowdStrike's CCFR-201 exam
Question #: 14
Topic #: 1
[All CCFR-201 Questions]

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Dean
28 days ago
Haha, this is a classic 'which two fields do you need' type of question. B is the obvious answer, but I'm chuckling at the thought of someone picking C and trying to do a timeline search on the 'ContextProcessld_decimal'. That would be a wild goose chase!
upvoted 0 times
Cyril
1 days ago
A) ParentProcessld_decimal and aid
upvoted 0 times
...
...
Twanna
1 months ago
I think B is the way to go. The question is specifically asking about the fields needed to find other files opened by the responsible process, so that's the logical choice.
upvoted 0 times
Carlota
3 days ago
I agree, B is the correct choice. Those fields will help us track down other files opened by the responsible process.
upvoted 0 times
...
Luis
8 days ago
I agree, ResponsibleProcessId_decimal and aid are the fields needed.
upvoted 0 times
...
Lavera
22 days ago
I think B is the way to go.
upvoted 0 times
...
...
Sherell
2 months ago
Definitely B. The question is asking for the fields needed to perform a Process Timeline search, and the ResponsibleProcessld_decimal and aid are the key pieces of information.
upvoted 0 times
Harrison
1 months ago
Yes, I agree. Those are the key fields needed for a Process Timeline search.
upvoted 0 times
...
Iola
1 months ago
I think the answer is B) ResponsibleProcessld_decimal and aid.
upvoted 0 times
...
...
Alverta
2 months ago
Actually, I checked the documentation and it says we need ParentProcessld_decimal and aid for the search.
upvoted 0 times
...
Toi
2 months ago
The correct answer seems to be B) ResponsibleProcessld_decimal and aid. That's the information I need to find out what other files were opened by the process responsible for the FileOpenlnfo event.
upvoted 0 times
Kathrine
3 days ago
I'm curious to see the results of the search based on those field values.
upvoted 0 times
...
Georgiann
18 days ago
Great, let's use that information to see what other files were opened.
upvoted 0 times
...
Leoma
24 days ago
Yes, you're right. Those are the field values needed for the Process Timeline search.
upvoted 0 times
...
Bo
1 months ago
I think the answer is B) ResponsibleProcessld_decimal and aid.
upvoted 0 times
...
...
Thurman
2 months ago
I disagree, I believe we need TargetProcessld_decimal and aid for the search.
upvoted 0 times
...
Alverta
2 months ago
I think we need ResponsibleProcessld_decimal and aid for Process Timeline search.
upvoted 0 times
...

Save Cancel