QuestionQ15

Policy Application

After Falcon has been successfully installed on a new employee’s laptop, you observe that the device is assigned the default prevention policy rather than the custom prevention policy you created. You confirm that the Falcon sensor is operating properly, and that the custom policy is enabled and running successfully on more than 1,000 other Falcon hosts.

What is the most likely cause of this issue?

  • A Falcon requires a 24-hour waiting period to apply custom policies to newly installed hosts
  • B A host-based firewall rule is preventing the custom policy from applying successfully
  • C The laptop is not a member of a host group assigned to the custom policy
  • D A prompt to apply the new prevention policy was manually declined
Explanation

Falcon prevention policies are assigned through host groups. A host that is not a member of a host group associated with the custom prevention policy remains assigned to the default prevention policy, even when its sensor is functioning and the custom policy is successfully applied to other hosts.

Community Discussion

No comments yet. Be the first to start the discussion!