CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 18: CCFH-202B: CrowdStrike Certified Falcon Hunter

Falcon has detected and prevented credential dumping activity on a domain controller. There were no obvious credential dumping tools identified in the detection. What is the next step in your investigation?

Nội dung câu hỏi

Falcon has detected and prevented credential dumping activity on a domain controller. There were no obvious credential dumping tools identified in the detection. What is the next step in your investigation?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Perform a PowerShell hunt across the environment
  2. B. Review dump sites and the dark web for the exposed credentials
  3. C. Perform an advanced event search and investigate the time window of events surrounding the alert — đáp án hiện tại
  4. D. Escalate the activity to your IT department and inquire if they are performing this activity

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề