nerdexam
CrowdStrike

CCFH-202B · Question #15

You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?

The correct answer is A. Events Data Dictionary. The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because it provides a reference of information about the events found in the Investigate > Event Search page of the Falcon Console. The Events Data Dictionary describes each event…

Falcon Platform Documentation and Resources

Question

You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?

Options

  • AEvents Data Dictionary
  • BStreaming API Event Dictionary
  • CHunting and Investigation
  • DEvent stream APIs

How the community answered

(36 responses)
  • A
    92% (33)
  • B
    6% (2)
  • D
    3% (1)

Explanation

The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because it provides a reference of information about the events found in the Investigate > Event Search page of the Falcon Console. The Events Data Dictionary describes each event type, field name, data type, description, and example value that can be used to query and analyze event data. The Streaming API Event Dictionary, Hunting and Investigation, and Event stream APIs are not documentation that provide details about key data fields and sensor events.

Topics

#Events Data Dictionary#Falcon documentation#sensor events#data fields

Community Discussion

No community discussion yet for this question.

Full CCFH-202B Practice