Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
Which of the following can a Falcon Administrator edit in an existing user's profile?
Which is a filter within the Host setup and management > Host management page?
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?
Which command would tell you if a Falcon Sensor was running on a Windows host?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
You want to create a detection-only policy. How do you set this up in your policy's settings?
Where can you modify settings to permit certain traffic during a containment period?
What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
When a host is placed in Network Containment, which of the following is TRUE?
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
What best describes what happens to detections in the console after clicking "Enable Detections" for a host which previously had its detections disabled?
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
Which of the following is TRUE regarding Falcon Next-Gen AntiVirus (NGAV)?
Which statement describes what is recommended for the Default Sensor Update policy?
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?
When creating new IOCs in IOC management, which of the following fields must be configured?
What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20-minute default provisioning window?
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?