CrowdStrike
CCFH-202B · Question #62
Suspicious RDP connections have been observed on a host within your environment. How do you utilize Event Search to show all connections on this specific host?
The correct answer is D. aid=[my-aid] event_simpleName=UserIdentity LogonType_decimal=10 | table timestamp. You've hit your limit · resets 12:50am (America/New_York)
Event Search and Query Construction
Question
Suspicious RDP connections have been observed on a host within your environment. How do you utilize Event Search to show all connections on this specific host?
Options
- Aevent_simpleName=UserIdentity LogonType_decimal=10 | table timestamp ComputerName
- BTable timestamp ComputerName UserName UserPrincipal LogonServer
- CUserIdentity=LogonType_decimal=10 | table timestamp UserPrincipal LogonServer
- Daid=[my-aid] event_simpleName=UserIdentity LogonType_decimal=10 | table timestamp
How the community answered
(62 responses)- A15% (9)
- B8% (5)
- C5% (3)
- D73% (45)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#Event Search#RDP#LogonType#query syntax
Community Discussion
No community discussion yet for this question.