Your CISO has decided all Falcon Analysts should also have the ability to view files and file contents locally on compromised hosts, but without the ability to take them off the host. What is the most appropriate role that can be added to fullfil
this requirement?
A. Remediation Manager
B. Real Time Responder ?Read Only Analyst
C. Falcon Analyst ?Read Only
D. Real Time Responder ?Active Responder
What statement is TRUE about managing a user's role?
A. The Administrator cannot re-use the account email for a new account
B. You must have Falcon MFA enabled first
C. You must be a Falcon Security Lead
D. You must be a Falcon Administrator
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?
A. .*badguydomain.com.*
B. \Device\HarddiskVolume2\*.exe -SingleArgument www.badguydomain.com /kill
C. badguydomain\.com.*
D. Custom IOA rules cannot be created for domains
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
A. Clone the workflow and replace the existing email with your CISO's email
B. Add a sequential action to send a custom email to your CISO
C. Add a parallel action to send a custom email to your CISO
D. Add the CISO's email to the existing action
Which is a filter within the Host setup and management > Host management page?
A. User name
B. OU
C. BIOS Version
D. Locality
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?
A. The API client secret can be viewed from the Edit API client pop-up box
B. Enable the Client Secret column to reveal the API client secret
C. Re-create the API client using the exact name to see the API client secret
D. The API client secret cannot be retrieved after it has been created
What is the purpose of the Default Sensor Policy?
A. A mechanism to deploy the oldest supported version of the Falcon Sensor.
B. Tests the sensor configuration settings before deployment.
C. Used to reset all sensor settings to Default.
D. Acts as a "catch all" policy if no other Sensor Policies are applied.
Where can you find your company's Customer ID (CID)?
A. The CID is a secret key used for Falcon communication and is never shared with the customer
B. The CID is only available by calling support
C. The CID is located at Hosts setup and management > Deploy > Sensor Downloads and is listed along with the checksum
D. The CID is located at Hosts > Host Management
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
A. 1
B. 2
C. 0
D. 3
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20-minute default provisioning window?
A. ExtendedWindow=1
B. Timeout=0
C. ProvNoWait=1
D. Timeout=30