| Exam Name: | CrowdStrike Certified Falcon Responder | ||
| Exam Code: | CCFR-201b Dumps | ||
| Vendor: | CrowdStrike | Certification: | CCFR |
| Questions: | 209 Q&A's | Shared By: | darla |
A responder has identified a suspicious PowerShell script executing on a domain controller. To perform a deep-dive forensic analysis of every action taken by that specific process—including network connections and file modifications—the analyst needs to pivot to a Process Timeline. What is the absolute minimum telemetry data required to generate this auto-filled view?
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
How long does detection data remain in the CrowdStrike Cloud before purging begins?