You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
A Falcon Administrator is trying to use Real-Time Response to start a session with a host that has a sensor installed but they are unable to connect. What is the most likely cause?
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20-minute default provisioning window?
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor Update Policy would meet this criteria?
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
The alignment of a particular prevention policy to one or more host groups can be completed in which of the following locations within Falcon?
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?
Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil this requirement?
What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?
Which Real Time Response role will allow you to see all analyst session details?
Why is it important to know your company's event data retention limits in the Falcon platform?
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
In order to quarantine files on the host, what prevention policy settings must be enabled?
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?
What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
You have been asked to troubleshoot why Script Based Execution Monitoring (SBEM) is not enabled on a Falcon host. Which report can be used to determine if this is an issue with an old prevention policy?
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
Which of the following uses Regex to create a detection or take a preventative action?
On the Host management page which filter could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform?
When creating new IOCs in IOC management, which of the following fields must be configured?
The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?