QuestionQ69
Falcon Fusion for Identity Protection
Given the Falcon Fusion workflow shown above, which of the following correctly describes this workflow?
- A For Anomalous RPC detections of any kind, the source endpoint will be network contained
- B For Anomalous RPC detections of any kind, the source endpoint will be added to a watchlist and network contained
- C Any Identity Protection detections for Anomalous RPC (ZeroLogon) will result in the source endpoint being added to the watchlist and network contained
- D Any Identity Protection detections for Anomalous RPC (ZeroLogon) will result in the source user being added to the watchlist and restricted from future logons
Community Discussion