What is the purpose of a containment policy?
How do you find a list of inactive sensors?
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
What is the name for the unique host identifier in Falcon assigned to each sensor during sensor installation?
How long are detection events kept in Falcon?
What can the Quarantine Manager role do?
When a host is placed in Network Containment, which of the following is TRUE?
What is the purpose of the Machine-Learning Prevention Monitoring Report?
Why would you assign hosts to a static group instead of a dynamic group?
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?