A member of your SECOPS team is building custom scripts for RTR, but they are unable to save or share them in Falcon. What additional role do they need?
What are the components that must be allowed to manually install Falcon Sensor on macOS?
After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?
How are sensor updates managed and enforced across multiple hosts in Falcon?
Which report provides a filterable high-level overview of host information such as OS version, Device Type and Machine Domain, and also provides an active sensor heat map for a quick environment review?
Your organization has determined that your cybersecurity architect needs to be notified via email whenever Falcon generates detections of a medium severity or higher. Additionally, the architect should be notified about any incidents with a CrowdScore of 1.0 or higher. What can the Falcon Administrator do to ensure the architect is properly alerted?
Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?
What best describes the relationship between Sensor Update policies and Operating Systems?
You will be testing detections with pentest and security tooling on your host. How can a workflow be created to automatically assign any detection related to your pentest to yourself in real time?
A Falcon Administrator is unable to initiate a Real-Time Response (RTR) session. What is the most likely cause?
You are tasked with creating a “Workstations†host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?
A new prevention policy has been created for assignment to the group named “Serversâ€. When you try to apply the policy, the “Servers†group is not available. What is the most likely reason the group is not available?
After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?
In addition to Host Groups, what other groups can a prevention policy be applied to?
Your leadership wants controls in place for immediate action on any Overwatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?
Which default user role will allow you to see all analyst session details?
Your incident responder team is migrating existing workflows into Fusion SOAR workflows so that they execute natively in Falcon. The workflow imports are failing. What format must the workflows be in order to successfully import them into Fusion SOAR?
During a Windows system investigation via Real Time Response, an RTR Active Responder is unable to execute a custom PowerShell script for finding specific system artifacts. What is likely restricting the responder from executing the PowerShell script?
You are deploying the Falcon sensor to 500 hosts. Hosts in an Organizational Unit need a specific exclusion that was previously identified. This OU is expected to add members over the next quarter. What is the best way to create a host group for this OU?
What prevention policy settings must be enabled to quarantine files on the host?
How can you search for multiple hostnames at the same time via Host Management?
Which Windows prevention policy setting monitors contents of shells for execution of malicious content?