the question is asking "system time of xxx". the "*FileWritten event" is the event, the focus is the system time, so the answer is A
Document : Falcon Documentation > Event Investigation > Events > Events Full Reference (Events Data Dictionary)
ContextTimeStamp_decimal
The time at which an event occurred on the system, as seen by the sensor (in decimal, non-hex format). Not to be confused with timestamp which is the time the event was received by the cloud.
(A) ContextTimeStamp_decimal: This field specifically refers to the time the event was captured by the security system, which is what you're interested in for a FileWritten event.
This section is not available anymore. Please use the main Exam Page.CCFH-202 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
examtopics3000
Highly Voted 1 year, 9 months agodpari
Most Recent 5 months, 2 weeks agoalanalanalan
10 months, 2 weeks agosilva222222
1 year agogr23
1 year, 3 months agoJoe_Kwok
1 year, 9 months ago