Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which setting inside the Sensor Update Policy prevents unauthorized uninstallation?

A.

Installation and Maintenance Protection

B.

Sensor Version Control Protection

C.

Uninstall and Maintenance Protection

D.

Update and Management Protection

You have 100 hashes that have been prohibited by management and need to be blocked within your organization. Using Falcon, what is the best way to accomplish this?

A.

Navigate to Configure > IOC Management. Add a custom IOC. Add the list of hashes. Set the action to Block. Verify the prevention policy includes Custom Blocking under Execution Blocking.

B.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block. Verify Custom Execution Blocking is active.

C.

Navigate to Configure > IOC Management. Add a custom Prevention Policy. Add the list of hashes. Set the action to Block. Verify the policy includes Custom Execution Blocking.

D.

Navigate to Configure > Prevention policies. Add an IOC Policy. Add the list of hashes as CSV file. Set the action to Block and Alert. Verify Custom Blocking inside Execution Blocking is active.

In addition to Host Groups, what other groups can a prevention policy be applied to?

A.

Operating System Groups

B.

Machine Learning Groups

C.

Custom IOA Rule Groups

D.

Custom IOC Groups

What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?

A.

It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious

B.

It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks

C.

It is designed to show malicious processes that would have been blocked in your environment based on different Machine-Learning Prevention settings

D.

It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined

After enabling an IOA rule and its respective rule group, what else must be done for an IOA to be fully functional?

A.

The rule must be manually triggered

B.

Hosts must be individually selected to apply to the rule

C.

The rule group must be assigned to a prevention policy

When using Microsoft Windows, what command verifies that a Falcon Sensor is running?

A.

cswindiag.exe -status

B.

sc.exe query csagent

C.

netstat.exe -f

D.

sc.exe query falcon

How are prevention policies assigned to hosts in the Falcon platform?

A.

Through host group membership

B.

Through direct host assignment

C.

Through IP address ranges

D.

Through manual configuration

What update policy does a sensor receive when it does not have a group assignment?

A.

Top precedence policy

B.

Default policy

C.

Auto N-1 policy

What is the primary purpose of custom IOA rules?

A.

Block known malware

B.

Identify malicious behavior

C.

Manage system updates

D.

Configure network settings

Detections related to a penetration test on a particular server are currently generating thousands of entries in the console. Your leadership does not need to track the detections in Falcon. What should you do to allow your team to focus on more relevant detections?

A.

Delete the detections in the console and contain the server undergoing the test

B.

Temporarily disable detections for the server in Host Management and reenable after the test is done

C.

Create a Fusion Workflow to email the SOC team every time the penetration test generates a detection

D.

Permanently disable detections for the server in Host Management