QuestionQ62

Host Management and Setup

A host has been network-contained with Falcon, and you have been asked to update its operating system with zero-day patches. You tried using your patch-update systems for this task, but their jobs fail.

Which Falcon UI configuration steps will allow these activities?

  • A Create a Containment Policy that allow lists the specific IP addresses of your patch management tools
  • B Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools
  • C Remove Host containment and update the host with all patches
  • D Create a Firewall Policy that allow lists your patch management tools
Explanation

A Falcon Containment Policy can allowlist the specific IP addresses of patch-management tools so a network-contained host can communicate with those systems while containment remains active. FQDN allowlisting is not the containment exception mechanism, and a Firewall Policy does not supersede Network Containment.

Community Discussion

No comments yet. Be the first to start the discussion!