CrowdStrike CCFR-201 Question Answer
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
CrowdStrike CCFR-201 Summary
- Vendor: CrowdStrike
- Product: CCFR-201
- Update on: Jul 31, 2025
- Questions: 60