<< Prev Question Next Question >>

Question 31/40

A process has created a number of interesting (executable) files in one sequence.
In addition to the event Subtype 'New Unapproved File to Computer', what other event subtype is likely to be associated with this sequence?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (40q)
Question 1: Which statement filters data to only return rows where the p...
Question 2: What does the Aggressive setting do when configured in Local...
Question 3: An administrator wants to query the status of the firewall f...
Question 4: Review this result after executing a query in the Process Se...
Question 5: Which identifier is shared by all events when an alert is in...
Question 6: An administrator wants to allow files to run from a network ...
Question 7: An administrator is reviewing an alert about a known and req...
Question 8: A watchlist generates a false positive on the Triage Alerts ...
Question 9: An administrator is interested in upgrading endpoints to the...
Question 10: Given an event rule: Approve nVidia Drivers, changes the loc...
Question 11: Why would a sensor have a status of "Inactive"?...
Question 12: An administrator is creating a query per policy for Audit an...
Question 13: An administrator has updated a Threat Intelligence Report by...
Question 14: An analyst wants to block an application's specific behavior...
Question 15: Which action is only available for the "Performs any operati...
Question 16: When dismissing alerts, when should an administrator select ...
Question 17: An administrator needs to manage a group of sensors from wit...
1 commentQuestion 18: An active compromise is detected on an endpoint. Due to curr...
Question 19: An analyst is investigating an alert within Enterprise EDR. ...
Question 20: An organization leverages a commonly used software distribut...
Question 21: An Endpoint Standard administrator is working with an IT tea...
Question 22: An Enterprise EDR administrator sees the process in the grap...
Question 23: An analyst is reviewing an alert in Enterprise EDR from a cu...
Question 24: An administrator needs to check configurations using Audit a...
Question 25: Refer to the exhibit, noting the circled red dot: (Exhibit) ...
Question 26: An administrator wants to find instances where the binary Is...
Question 27: What is the maximum number of binaries (hashes) that can be ...
Question 28: A Carbon Black Cloud analyst needs to identify the Internet ...
Question 29: An administrator ran the following query. SELECT name, VERSI...
Question 30: An Enterprise EDR administrator has created a custom Watchli...
Question 31: A process has created a number of interesting (executable) f...
Question 32: An Enterprise EDR administrator wants to use Watchlists cura...
Question 33: Which statement is true when searching through the EDR serve...
Question 34: Level 3 service desk personnel have been approved to modify ...
Question 35: Given the following query: SELECT * FROM users WHERE UID &gt...
Question 36: An administrator uses the following Enterprise EDR search qu...
Question 37: An analyst on the security team noticed that several alerts ...
Question 38: Which value should an administrator use when reviewing an al...
Question 39: There is a need to ignore all activity at an application pat...
Question 40: This search is entered into the process search page: notepad...