Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

What information can be found in the Real Time Response (RTR) Audit Log?

A.

IP Address, Prevention Policy, recent detections, and host group assignment

B.

Session end time, command return results, and file activity

C.

Session start time, duration, user, hostname, commands used, and retrieved files

D.

Real Time Response (RTR) information is not collected via audit logs

An inactive host that does not contact the Falcon cloud will be automatically removed from the Host Management and Trash pages after how many days?

A.

75 Days

B.

60 Days

C.

90 Days

D.

45 Days

A host has been Network contained with Falcon and you have been asked to update the Operating System with zero day patches. You have tried using your patch update systems for this task, but the jobs fail. Which configuration steps in the Falcon UI will allow these activities?

A.

Create a Containment Policy that allow lists the specific IP addresses of your patch management tools

B.

Create a Containment Policy that allow lists the Fully Qualified name of your patch management tools

C.

Remove Host containment and update the host with all patches

D.

Create a Firewall Policy that allow lists your patch management tools

What is an example of when you will need to refer to your Customer ID+ Checksum (CIDC)?

A.

When uninstalling a Falcon Sensor

B.

When you need to find a specific host in Host Management

C.

When defining host group assignment criteria

D.

When installing a new Falcon Sensor

You can create Fusion SOAR workflows to precisely define the actions you want Falcon to perform in response to incidents. Which three items must be defined in every trigger so that it executes successfully?

A.

Trigger, Condition, Action

B.

Rule Type, Condition, Action

C.

Rule Type, Filter, Objective

D.

Trigger, Filter, Objective

You have created a new static host group to test a newly created sensor update policy, and need to add 500 servers into the group. You want to upload a list of hosts to Falcon for automatic addition into the group. What file format must the list be for this to be successfully accomplished?

A.

XLSX

B.

PDF

C.

TXT

D.

JSON

What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?

A.

All detection data for the host is deleted and the host is hidden from view

B.

Existing detections for the host remain

C.

New detections are disabled for 30 days

D.

The detections for the host are removed from the console immediately

There are a significant number of false positive detections from your developers that are getting blocked and quarantined by Falcon. What Indicator of Compromise (IOC) action would be the best option?

A.

Detect Only

B.

Allow

C.

Prevent

D.

No action

Where can you find the history of the successes and failures for any Fusion SOAR workflows?

A.

Falcon UI Audit Trail

B.

Custom Alert History

C.

Workflow Audit log

D.

Workflow Execution log

What policy setting should be selected for a new host when it has an existing antivirus?

A.

Extra Aggressive Level ML

B.

Aggressive Level ML

C.

Moderate Level ML

D.

Cautious Level ML