nerdexam
CrowdStrike

CCFR-201B · Question #53

You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would you input this…

The correct answer is A. IP Addresses. You've hit your limit · resets 12:50am (America/New_York)

Investigation and Threat Hunting

Question

You receive an email from a third-party vendor that one of their services is compromised, the vendor names a specific IP address that the compromised service was using. Where would you input this indicator to find any activity related to this IP address?

Options

  • AIP Addresses
  • BRemote or Network Logon Activity
  • CRemote Access Graph
  • DHash Executions

How the community answered

(30 responses)
  • A
    90% (27)
  • C
    3% (1)
  • D
    7% (2)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#IP investigation#indicator search#threat hunting#Falcon Investigate

Community Discussion

No community discussion yet for this question.

Full CCFR-201B Practice