Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike CCFR-201b Exam - Topic 5 Question 8 Discussion

Actual exam question for CrowdStrike's CCFR-201b exam
Question #: 8
Topic #: 5
[All CCFR-201b Questions]

You found a list of SHA256 hashes in an intelligence report and search for them using the Hash Execution Search. What can be determined from the results?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Hash Execution Search tool allows you to search for one or more SHA256 hashes and view a summary of information from Falcon events that contain those hashes1.The summary includes the hostname, sensor ID, OS, country, city, ISP, ASN, and geolocation of the host that loaded or executed those hashes1.You can also see a count of detections and incidents related to those hashes1.


Contribute your Thoughts:

0/2000 characters
Jesusita
2 days ago
I think the answer might be B, since it seems like it would show where those hashes were executed.
upvoted 0 times
...

Save Cancel