Your security team is noticing that certain privacy-sensitive information such as the URL, HTTP Header and POST bodies are missing from HTTP related detections. What is likely the cause for this?
You are tasked with creating a group for hosts running Windows 10. What kind of group should you create to make sure all applicable hosts are included in your environment?
What type of information is provided in sensor health report?
Which Windows prevention policy setting monitors contents of shells for execution of malicious content?
Which role allows management of quarantined files?
What are the components that must be allowed to manually install Falcon Sensor on macOS?
What default user role can manage API credentials?
What is the recommended approach for managing host groups over time?
How are prevention policies assigned to hosts in the Falcon platform?
Your organization wants to monitor the use of remote access software that is currently authorized. The executable is called remote.exe. How would you trigger a detection for review of any process named remote.exe?
To improve the organization’s security posture, you are designing a Fusion SOAR workflow to generate an alert when critical vulnerabilities are detected by Falcon. When creating a new workflow from scratch, what component of the workflow must be configured first?
When would the No Action option be assigned to a hash in IOC Management?
Which default user role will allow you to see all analyst session details?
Why would you add IP addresses to a containment policy?
What is true about User Accounts created by the Falcon Administrator?
You want to add an additional layer of security to high-risk Real Time Response commands for your environment. Where do you configure MFA for RTR within the UI?
What update policy does a sensor receive when it does not have a group assignment?
What is the primary concern with Windows sensors going into Reduced Functionality Mode?
What is the highest level of protection for a prevention policy?
When troubleshooting a Windows sensor that appears to be installed but is not running, what should be verified to ensure they are installed and running?
When using Microsoft Windows, what command verifies that a Falcon Sensor is running?
What are the three required parts of a Fusion SOAR workflow condition?
You need to look up a Red Hat Enterprise Linux (RHEL) system in Host Management. What filter would apply?
Excluding mobile devices, what kind of hosts can be contained in Falcon?
Your leadership wants controls in place for immediate action on any Overwatch detections. What should you do to ensure the host is contained quickly and notifies the appropriate staff?
What page provides a count of new Reduced Functionality Mode (RFM) sensors by day?
A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?
You are tasked with creating a “Workstations” host group to encompass all workstations in your environment. Which dynamic grouping criteria will most efficiently accomplish this task?
You are assigning sensor group tags during installation. What is the maximum allowed length of all tags?