In the context of raw event searching, the term ' ProcessRollup2 ' refers to a value within which field?
While the host timeline is comprehensive, some data is not included in that specific view. Which of the following CANNOT be seen directly from the host timeline?
Falcon uses specific identifiers to track processes across the environment. Which of the following sentences best describes what the ' TargetProcessId_decimal ' raw data represents?
To manage the lifecycle of security incidents and review new alerts, a responder must navigate through the Falcon sidebar to which specific location?
Responders use ' IP Search ' to track connections to malicious infrastructure. Which of the following statements about the IP Search is FALSE?
In the Falcon console, detections can be automated or manual. Which of the following options represents a manual detection?
Depending on the subscription level, " Cloudable Events " (standard telemetry) have a specific retention period. What is the minimum period of time that these events are retained?