QuestionQ69

Falcon Fusion for Identity Protection

Question Image

Given the Falcon Fusion workflow shown above, which of the following correctly describes this workflow?

  • A For Anomalous RPC detections of any kind, the source endpoint will be network contained
  • B For Anomalous RPC detections of any kind, the source endpoint will be added to a watchlist and network contained
  • C Any Identity Protection detections for Anomalous RPC (ZeroLogon) will result in the source endpoint being added to the watchlist and network contained
  • D Any Identity Protection detections for Anomalous RPC (ZeroLogon) will result in the source user being added to the watchlist and restricted from future logons
Explanation

An Identity Protection detection named Anomalous RPC (ZeroLogon) satisfies the workflow condition. The configured actions add the source endpoint to a watchlist and contain the device, which network-contains that endpoint.

Community Discussion

No comments yet. Be the first to start the discussion!