Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike Exam CCFR-201 Topic 1 Question 14 Discussion

Actual exam question for CrowdStrike's CCFR-201 exam
Question #: 14
Topic #: 1
[All CCFR-201 Questions]

You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Dean
1 months ago
Haha, this is a classic 'which two fields do you need' type of question. B is the obvious answer, but I'm chuckling at the thought of someone picking C and trying to do a timeline search on the 'ContextProcessld_decimal'. That would be a wild goose chase!
upvoted 0 times
Evette
9 days ago
C) ContextProcessld_decimal and aid
upvoted 0 times
...
Felix
10 days ago
B) ResponsibleProcessld_decimal and aid
upvoted 0 times
...
Cyril
17 days ago
A) ParentProcessld_decimal and aid
upvoted 0 times
...
...
Twanna
2 months ago
I think B is the way to go. The question is specifically asking about the fields needed to find other files opened by the responsible process, so that's the logical choice.
upvoted 0 times
Dana
1 days ago
Sounds good, let's see what other files were opened by the responsible process.
upvoted 0 times
...
Yong
2 days ago
Let's use those to perform a Process Timeline search.
upvoted 0 times
...
Peggie
5 days ago
I'm not sure, but I think D could also work. It's important to consider all possibilities when conducting a Process Timeline search.
upvoted 0 times
...
Loren
15 days ago
I think A might also be useful. It's always good to have multiple options when searching for information like this.
upvoted 0 times
...
Carlota
19 days ago
I agree, B is the correct choice. Those fields will help us track down other files opened by the responsible process.
upvoted 0 times
...
Luis
24 days ago
I agree, ResponsibleProcessId_decimal and aid are the fields needed.
upvoted 0 times
...
Lavera
1 months ago
I think B is the way to go.
upvoted 0 times
...
...
Sherell
2 months ago
Definitely B. The question is asking for the fields needed to perform a Process Timeline search, and the ResponsibleProcessld_decimal and aid are the key pieces of information.
upvoted 0 times
Harrison
2 months ago
Yes, I agree. Those are the key fields needed for a Process Timeline search.
upvoted 0 times
...
Iola
2 months ago
I think the answer is B) ResponsibleProcessld_decimal and aid.
upvoted 0 times
...
...
Alverta
2 months ago
Actually, I checked the documentation and it says we need ParentProcessld_decimal and aid for the search.
upvoted 0 times
...
Toi
2 months ago
The correct answer seems to be B) ResponsibleProcessld_decimal and aid. That's the information I need to find out what other files were opened by the process responsible for the FileOpenlnfo event.
upvoted 0 times
Kathrine
19 days ago
I'm curious to see the results of the search based on those field values.
upvoted 0 times
...
Georgiann
1 months ago
Great, let's use that information to see what other files were opened.
upvoted 0 times
...
Leoma
1 months ago
Yes, you're right. Those are the field values needed for the Process Timeline search.
upvoted 0 times
...
Bo
2 months ago
I think the answer is B) ResponsibleProcessld_decimal and aid.
upvoted 0 times
...
...
Thurman
2 months ago
I disagree, I believe we need TargetProcessld_decimal and aid for the search.
upvoted 0 times
...
Alverta
2 months ago
I think we need ResponsibleProcessld_decimal and aid for Process Timeline search.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77