How does the Unique Hosts Connecting to Countries Map help an administrator?
When editing an existing IOA exclusion, what can NOT be edited?
How many days will an inactive host remain visible within the Host Management or Trash pages?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
What can exclusions be applied to?
If a user wanted to install an older version of the Falcon sensor, how would they find the older installer file?
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?
When the Notify End Users policy setting is turned on, which of the following is TRUE?
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?