When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
What best describes what happens to detections in the console after clicking "Enable Detections" for a host which previously had its detections disabled?
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?
What is the purpose of precedence with respect to the Sensor Update policy?
Where can you modify settings to permit certain traffic during a containment period?
On which page of the Falcon console would you create sensor groups?
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?
What is the purpose of using groups with Sensor Update policies in CrowdStrike Falcon?
Which of the following scenarios best describes when you would add IP addresses to the containment policy?
What can the Quarantine Manager role do?
When would the No Action option be assigned to a hash in IOC Management?
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
When a Linux host is in Reduced Functionality Mode (RFM) what telemetry and protection is still offered?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
Which role will allow someone to manage quarantine files?
What impact does disabling detections on a host have on an API?
When troubleshooting the Falcon Sensor on Windows, what is the correct parameter to output the log directory to a specified file?
A Falcon Administrator is trying to use Real-Time Response to start a session with a host that has a sensor installed but they are unable to connect. What is the most likely cause?
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?
What three things does a workflow condition consist of?
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
On which page of the Falcon console can one locate the Customer ID (CID)?
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
Why is it important to know your company's event data retention limits in the Falcon platform?
Which of the following is NOT an available action for an API Client?
Which command would tell you if a Falcon Sensor was running on a Windows host?
Which report lists counts of sensors in Reduced Functionality Mode (RFM) for all operating system types, and tracks how long a sensor version will be supported?
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
Which of the following is TRUE regarding disabling detections for a host?
An administrator creating an exclusion is limited to applying a rule to how many groups of hosts?
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?
Why is the ability to disable detections helpful?
How many days will an inactive host remain visible within the Host Management or Trash pages?