QuestionQ11

Rules Configuration

Detections associated with a penetration test on a particular server are currently producing thousands of entries in the console. Leadership does not need to monitor these detections in Falcon.

What should you do so the team can focus on more relevant detections?

  • A Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection
  • B Implement an SVE on the particular host
  • C Temporarily disable detections for the server in Host Management and re-enable after the test is done
  • D Use Real Time Response (RTR) to kill the offending process on the server
Explanation

A Sensor Visibility Exclusion (SVE) suppresses the unwanted detection visibility from authorized penetration-testing activity on the scoped host, reducing console noise while allowing the team to concentrate on relevant detections.

Community Discussion

No comments yet. Be the first to start the discussion!