QuestionQ77
Rules ConfigurationDetections associated with a penetration test on a particular server are producing thousands of console entries. Leadership does not need to monitor these detections in Falcon.
What should you do so the team can focus on more relevant detections?
- A Delete the detections in the console and contain the server undergoing the test
- B Temporarily disable detections for the server in Host Management and reenable after the test is done
- C Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection
- D Permanently disable detections for the server in Host Management
Community Discussion