Question 6

What should you do with a field that is not CPS-compliant when adding it to a parser?
  • Question 7

    An analyst needs to identify lateral movement using PowerShell across endpoints leveraging CrowdStrike data integrated into the SIEM platform.
  • Question 8

    Which metric best reflects how quickly a SIEM-enabled SOC can respond to detected threats from identification to remediation?
  • Question 9

    When deploying the Falcon Log Collector using the commands in the CrowdStrike Fleet Management interface, what is the correct service name?
  • Question 10

    An internal security team identified a small number of high-risk users. They ask you to create an app that will monitor these users and trigger an alert when specific suspicious behavior is detected.
    Which Falcon feature should you use to develop this app?