Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFR-201b Exam - Topic 5 Question 12 Discussion

You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
D) Process ID or Parent Process ID
A) ProcessTimeline Link
B) PID
C) UTCtime

CrowdStrike CCFR-201b Exam - Topic 5 Question 12 Discussion

Actual exam question for CrowdStrike's CCFR-201b exam
Question #: 12
Topic #: 5
[All CCFR-201b Questions]

You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?

Show Suggested Answer Hide Answer
Suggested Answer: D

According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc1.The tool requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID)1.You can jump to a Process Timeline from many views, such as Hash Search, Host Timeline, Event Search, etc., by clicking on either the Process ID or Parent Process ID fields in those views1.This will automatically populate the aid and TargetProcessId_decimal parameters for the Process Timeline tool1.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel