nerdexam
CrowdStrike

CCFH-202B · Question #20

Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined…

The correct answer is B. Hunting and Investigation. The Hunting and Investigation document provides information on best practices for writing Splunk- based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious…

Falcon Platform Documentation and Resources

Question

Which document provides information on best practices for writing Splunk-based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes?

Options

  • AReal Time Response and Network Containment
  • BHunting and Investigation
  • CEvents Data Dictionary
  • DIncident and Detection Monitoring

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • D
    3% (1)

Explanation

The Hunting and Investigation document provides information on best practices for writing Splunk- based hunting queries, predefined queries which may be customized to hunt for suspicious network connections, and predefined queries which may be customized to hunt for suspicious processes. As explained above, the Hunting and Investigation document is a guide that provides sample hunting queries, select walkthroughs, and best practices for hunting with Falcon. The other documents do not provide the same information.

Topics

#Hunting and Investigation Guide#Splunk hunting queries#best practices#predefined queries

Community Discussion

No community discussion yet for this question.

Full CCFH-202B Practice