Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
the question is asking "system time of xxx". the "*FileWritten event" is the event, the focus is the system time, so the answer is A
Document : Falcon Documentation > Event Investigation > Events > Events Full Reference (Events Data Dictionary)
ContextTimeStamp_decimal
The time at which an event occurred on the system, as seen by the sensor (in decimal, non-hex format). Not to be confused with timestamp which is the time the event was received by the cloud.
(A) ContextTimeStamp_decimal: This field specifically refers to the time the event was captured by the security system, which is what you're interested in for a FileWritten event.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
examtopics3000
Highly Voted 11 months, 1 week agoalanalanalan
Most Recent 1 week, 4 days agosilva222222
2 months agogr23
5 months, 4 weeks agoJoe_Kwok
11 months, 1 week ago