nerdexam
CrowdStrike

CCFH-202B · Question #86

During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all files written to…

The correct answer is A. event_simpleName=*written ComputerName=MyPC ContextProcessId_decimal=0123456789. You've hit your limit · resets 12:50am (America/New_York)

Threat Investigation and Hunting

Question

During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all files written to your host by this process. What Splunk search would work for this scenario?

Options

  • Aevent_simpleName=*written ComputerName=MyPC ContextProcessId_decimal=0123456789
  • Bevent_simpleName=processrollup ComputerName=MyPC
  • Cevent_simpleName=*written ComputerName=MyPC TargetProcessId_decimal=0123456789
  • Devent_simpleName=processrollup ComputerName=MyPC

How the community answered

(22 responses)
  • A
    82% (18)
  • B
    5% (1)
  • C
    5% (1)
  • D
    9% (2)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#file write events#ContextProcessId_decimal#process investigation#malware hunting

Community Discussion

No community discussion yet for this question.

Full CCFH-202B Practice