You need to create a “Workstations” host group that includes ALL workstations in your environment.
Which dynamic-grouping criterion would best achieve this objective?
APlatform: Windows
BSite: Workstation
CGrouping Tags: Workstation
DType: Workstation
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Dashboards and Reports
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Policy Application
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Sensor Deployment
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Workflows
0
Community Discussion
No comments yet. Be the first to start the discussion!
What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?
AIt is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious
BIt is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
CIt is designed to show malicious processes that would have been blocked in your environment based on different Machine-Learning Prevention settings
DIt is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
When creating an API client, which two pieces of information must be generated together to successfully identify and validate your API integrations?
ACustomer ID and Integration ID
BClient ID and Secret
CCustomer ID and Secret
DClient ID and OAuth2 ID
Which components must be permitted to manually install Falcon Sensor on macOS?
ANetwork filter extension and Full Disk Access only
BFull Disk Access and System extension only
CNetwork filter extension and System extension only
DSystem extension, Full Disk Access, and Network filter extension
You will test detections on your host using pentest and security tooling.
How can you create a workflow that automatically assigns to you, in real time, any detection associated with your pentest?
ACreate an Event trigger workflow that triggers on an EPP Detection with an action to assign the detection to yourself
BCreate an Event trigger workflow that triggers on an EPP Detection with conditions looking for the desired hostname
CCreate an alert on usage of the tools and assign the alerts to you automatically via workflow
DCreate an IOC for the host to trigger associated detections and assign them to you via workflow
QuestionQ6
Workflows
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Policy Application
QuestionQ8
Policy Application
QuestionQ9
User Management
QuestionQ10
Host Management and Setup
QuestionQ11
Rules Configuration
QuestionQ12
Sensor Deployment
QuestionQ13
Policy Application
QuestionQ14
Host Management and Setup
QuestionQ15
Policy Application
QuestionQ16
Host Management and Setup
QuestionQ17
Group Creation
QuestionQ18
Sensor Deployment
QuestionQ19
Policy Application
QuestionQ20
Host Management and Setup
QuestionQ22
User Management
QuestionQ23
Host Management and Setup
QuestionQ24
Dashboards and Reports
QuestionQ25
Policy Application
QuestionQ26
Rules Configuration
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
What are the three mandatory components of a Fusion SOAR workflow condition?
AOperator, value, and source
BAlert, action, and schedule
CTrigger, parameter, and alert
DParameter, operator, and value
Which prevention-policy phase provides the highest level of protection?
APhase 1
BPhase 2
CPhase 3
How can Falcon be enabled to quarantine files?
AThrough Prevention policy settings
BThrough General Settings
CThrough manual file deletion
DThrough system restore
Which statement is true about User Accounts created by the Falcon Administrator?
ABy default, all User Accounts are created with the Falcon Analyst role
BAll User Accounts must be created with an email address from the list of approved domains
CAll User Accounts must start with the domain identifier and number
DAll new User Accounts are created using an employee identification number (EID)
When searching for a host network address, which IP notation should you use?
A10.10.10.5;10.10.10.8
B10.10.10.2,10.10.10.7
C192.168.5.1/24
D192.168.5.1-100
Detections associated with a penetration test on a particular server are currently producing thousands of entries in the console. Leadership does not need to monitor these detections in Falcon.
What should you do so the team can focus on more relevant detections?
ACreate a Fusion Workflow to email the SOC team every time the penetration test generates a detection
BImplement an SVE on the particular host
CTemporarily disable detections for the server in Host Management and re-enable after the test is done
DUse Real Time Response (RTR) to kill the offending process on the server
What is the main concern when Windows sensors enter Reduced Functionality Mode (RFM)?
AThe operating systems on these hosts have crashed
BThe hosts have been powered off or otherwise cannot communicate with the Falcon cloud
CThe sensors do not have full visibility into all events occurring on the host
DThe sensors are unable to report any of their recorded events
Your organization has concluded that its cybersecurity architect must receive an email whenever Falcon generates detections with medium severity or higher. In addition, the architect must be notified of any incidents with a CrowdScore of 1.0 or higher.
What can the Falcon Administrator do to ensure the architect receives the appropriate alerts?
ACreate a new Falcon user for the architect then create and assign a custom Falcon user role so they are automatically notified for the new detections and emails
BCreate a custom Fusion SOAR workflow to send an email every time a new detection or incident is created
CAdd the architect’s email address to the manage list for detection and incident emails from the General settings menu
DCreate a new Falcon user for the architect and assign the Detections and Exceptions Manager role so they are automatically notified for the new detections and incidents
What is one situation in which you would need to refer to your Customer ID+ Checksum (CIDC)?
AWhen uninstalling a Falcon Sensor
BWhen you need to find a specific host in Host Management
CWhen defining host group assignment criteria
DWhen installing a new Falcon Sensor
After Falcon has been successfully installed on a new employee’s laptop, you observe that the device is assigned the default prevention policy rather than the custom prevention policy you created. You confirm that the Falcon sensor is operating properly, and that the custom policy is enabled and running successfully on more than 1,000 other Falcon hosts.
What is the most likely cause of this issue?
AFalcon requires a 24-hour waiting period to apply custom policies to newly installed hosts
BA host-based firewall rule is preventing the custom policy from applying successfully
CThe laptop is not a member of a host group assigned to the custom policy
DA prompt to apply the new prevention policy was manually declined
How can multiple hostnames be searched simultaneously through Host Management?
AEnter the multiple hostnames in the Hostname filter separating each by a comma
BAdd the Hostname filter multiple times and enter separate hostnames into each filter
CEnter the multiple hostnames in the Hostname filter separating each by a decimal
DAdd the Multiple Hostnames filter and enter your list of hostnames
You are deploying the Falcon sensor to 500 hosts in total. Hosts within an Organizational Unit (OU) require a specific exclusion that has already been identified. This OU is expected to gain members during the next quarter.
What is the best method for creating a host group for this OU?
ACreate a Dynamic Group targeting Windows 10 OS in the domain
BCreate a dynamic group with an assignment rule that excludes the OU
CCreate a dynamic group with an assignment rule that filters for the OU
When the Falcon Sensor is installed manually on Microsoft Windows, where is its installation log data stored?
A%LOCALAPPDATA%\Temp
B%SYSTEMROOT%\Temp
C%SYSTEMROOT%\Logs
D%LOCALAPPDATA%\Logs
Which statement best characterizes the relationship between Sensor Update policies and Operating Systems?
AA Sensor Update policy must be configured for each Operating System (Windows, Mac, Linux)
BSensor Update polices are not Operating System specific; one policy can be applied to all Operating Systems
CWindows has its own Sensor Update polices; Mac and Linux share Sensor Update policies
DWindows and Mac share Sensor Update policies; Linux requires its own set of polices based on the different kernel versions
On the Host management page, which field is best to filter by for Domain Controllers in order to obtain sensor version information?
ASensor Version
BType
CPlatform
DOS Version
Which role permits management of quarantined files?
AFalcon Analyst – Read Only
BDetections Exceptions Manager
CFalcon Security Lead
DEndpoint Manager
A Falcon Administrator cannot initiate a Real-Time Response (RTR) session.
What is the most likely reason?
AThe domain controller is preventing the connection
BThe host has a user logged into it
CThere is another analyst connected into it
DThey do not have an RTR role assigned to them
Which log would you use to investigate unusual activity involving a script that interacts with the Falcon platform?
AAPI audit
BFalcon UI audit
CPrevention policy debug
DRTR session audit
To quarantine files on the host, which prevention policy settings must be enabled?
AMalware Protection and Windows Anti-Malware Execution Blocking
BNext-Gen Antivirus Prevention sliders and “Quarantine & Security Center Registration”
CMalware Protection and Custom Execution Blocking
DBehavior-Based Threat Prevention sliders and Advanced Remediation Actions
Your organization wants to monitor use of currently authorized remote-access software. The executable is named remote.exe.
How would you trigger a detection for review whenever a process named remote.exe runs?
AWrite an IOA rule to monitor process creation of .*\remote.exe
BCreate an exclusion for remote.exe and set a workflow to email you every time the exclusion is used
CWrite a scheduled search looking for ProcessRollup2 events for remote.exe
Community Discussion