You have a Windows host on your network in Reduced functionality mode (RFM). While the system is in RFM, which of the following is TRUE?
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?
The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
When troubleshooting the Falcon Sensor on Windows, what is the correct parameter to output the log directory to a specified file?
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?
On the Host management page which filter could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform?
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor Update Policy would meet this criteria?
On a Windows host, what is the best command to determine if the sensor is currently running?
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however, when applying the new prevention policy this group is not appearing in the list of available groups. What is the most likely issue?
How can a Falcon Administrator configure a pop-up message to be displayed on a host when the Falcon sensor blocks, kills or quarantines an activity?
Which of the following scenarios best describes when you would add IP addresses to the containment policy?
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
Which of the following can a Falcon Administrator edit in an existing user's profile?
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
You want to create a detection-only policy. How do you set this up in your policy's settings?
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
Under the "Next-Gen Antivirus: Cloud Machine Learning" setting there are two categories, one of them is "Cloud Anti-Malware" and the other is:
Which is the correct order for manually installing a Falcon Package on a macOS system?
When a host belongs to more than one host group, how is sensor update precedence determined?