What is an advantage of using the IP Search tool?
What is the difference between Managed and Unmanaged Neighbors in the Falcon console?
What action is used when you want to save a prevention hash for later use?
After running an Event Search, you can select many Event Actions depending on your results. Which of the following is NOT an option for any Event Action?
What does pivoting to an Event Search from a detection do?
Which statement is TRUE regarding the "Bulk Domains" search?
What information is contained within a Process Timeline?
What types of events are returned by a Process Timeline?
When examining a raw DNS request event, you see a field called ContextProcessld_decimal. What is the purpose of that field?
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in .CSV format?