CCFH-202B · Question #42
Which of the following is an example of a Falcon threat hunting lead?
The correct answer is A. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from. A Falcon threat hunting lead is a piece of information that can be used to initiate or guide a threat hunting activity within the Falcon platform. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories is an…
Question
Which of the following is an example of a Falcon threat hunting lead?
Options
- AA routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from
- BSecurity appliance logs showing potentially bad traffic to an unknown external IP address
- CA help desk ticket for a user clicking on a link in an email causing their machine to become
- DAn external report describing a unique 5 character file extension for ransomware encrypted files
How the community answered
(40 responses)- A75% (30)
- B15% (6)
- C8% (3)
- D3% (1)
Explanation
A Falcon threat hunting lead is a piece of information that can be used to initiate or guide a threat hunting activity within the Falcon platform. A routine threat hunt query showing process executions of single letter filename (e.g., a.exe) from temporary directories is an example of a Falcon threat hunting lead, as it can indicate potential malicious activity that can be further investigated using Falcon data and features. Security appliance logs, help desk tickets, and external reports are not examples of Falcon threat hunting leads, as they are not directly related to the Falcon platform or data.
Topics
Community Discussion
No community discussion yet for this question.