Podcast
Questions and Answers
What type of user is C.Falcon Analyst considered?
What type of user is C.Falcon Analyst considered?
- Read Only User
- Active Responder
- Read Only Analyst (correct)
- User with administrator privileges
What setting would effectively reduce false positives for development work stored in 'devcode'?
What setting would effectively reduce false positives for development work stored in 'devcode'?
- Application Whitelisting
- Containment Policy (correct)
- Firewall Rule Group
- USB Device Policy
What action can you take to disable all detections for a host?
What action can you take to disable all detections for a host?
- Reinstall the agent to reset its configuration
- Request support to remove the machine from the detection list
- Create an exclusion rule and apply it to the machine (correct)
- Disable the notification settings on the agent
Which of the following options is least likely to reduce false positives during testing?
Which of the following options is least likely to reduce false positives during testing?
What is the primary role of an Active Responder in the context provided?
What is the primary role of an Active Responder in the context provided?
Which policy would you implement if you wanted to prevent USB devices from being used?
Which policy would you implement if you wanted to prevent USB devices from being used?
What would happen if false positives are not managed in an enterprise application development environment?
What would happen if false positives are not managed in an enterprise application development environment?
What is a drawback of contacting support to disable detections on a host?
What is a drawback of contacting support to disable detections on a host?
What is the only method to blocklist hashes?
What is the only method to blocklist hashes?
How many 'Auto' sensor version update options are available for Windows Sensor Update Policies?
How many 'Auto' sensor version update options are available for Windows Sensor Update Policies?
Where can the alignment of a prevention policy to host groups be configured within Falcon?
Where can the alignment of a prevention policy to host groups be configured within Falcon?
Which of the following options describes a misconception about Auto sensor update options?
Which of the following options describes a misconception about Auto sensor update options?
What should be expected when trying to configure policy alignment in Falcon for a prevention policy?
What should be expected when trying to configure policy alignment in Falcon for a prevention policy?
Which of the following is NOT a valid location for configuring policy alignment?
Which of the following is NOT a valid location for configuring policy alignment?
Which statement is true regarding auto updates for the Windows Sensor?
Which statement is true regarding auto updates for the Windows Sensor?
What is the misconception about the host group alignment configuration?
What is the misconception about the host group alignment configuration?
What cannot be retrieved after it has been created?
What cannot be retrieved after it has been created?
Which port and protocol is utilized by the sensor to communicate with the CrowdStrike Cloud?
Which port and protocol is utilized by the sensor to communicate with the CrowdStrike Cloud?
Where can you find the Windows sensor installer for CrowdStrike Falcon?
Where can you find the Windows sensor installer for CrowdStrike Falcon?
What is the significance of TCP port 443 in relation to CrowdStrike's sensor?
What is the significance of TCP port 443 in relation to CrowdStrike's sensor?
Why might sensor installers for CrowdStrike be unique to each customer?
Why might sensor installers for CrowdStrike be unique to each customer?
Which item must be saved immediately when creating an API client because it cannot be viewed again later?
Which item must be saved immediately when creating an API client because it cannot be viewed again later?
What is the most likely cause for multiple Windows hosts to be in Reduced Functionality Mode (RFM)?
What is the most likely cause for multiple Windows hosts to be in Reduced Functionality Mode (RFM)?
In what scenario would a 'Client ID' need to be saved during API client creation?
In what scenario would a 'Client ID' need to be saved during API client creation?
When troubleshooting a system in Reduced Functionality Mode, which action would be least likely to resolve the issue?
When troubleshooting a system in Reduced Functionality Mode, which action would be least likely to resolve the issue?
Which of the following best describes a consequence of a misconfigured Sensor Update Policy?
Which of the following best describes a consequence of a misconfigured Sensor Update Policy?
What should you check if a host has been offline for over 24 hours concerning RFM?
What should you check if a host has been offline for over 24 hours concerning RFM?
What does Reduced Functionality Mode (RFM) often indicate about a system's health?
What does Reduced Functionality Mode (RFM) often indicate about a system's health?
Why is it crucial to properly configure a Sensor Update Policy?
Why is it crucial to properly configure a Sensor Update Policy?
What must be enabled for effective malware protection in Windows?
What must be enabled for effective malware protection in Windows?
Why is it necessary to have separate sensor update policies for different operating systems?
Why is it necessary to have separate sensor update policies for different operating systems?
How can you assign a policy to a specific group of hosts?
How can you assign a policy to a specific group of hosts?
What is a primary reason for using Behavior-Based Threat Prevention?
What is a primary reason for using Behavior-Based Threat Prevention?
Which of the following is NOT a factor in assigning sensor update policies?
Which of the following is NOT a factor in assigning sensor update policies?
What does enabling Advanced Remediation Actions typically involve?
What does enabling Advanced Remediation Actions typically involve?
What could be a consequence of not having separate sensor policies for each OS?
What could be a consequence of not having separate sensor policies for each OS?
What is the primary focus of Community voting distribution in policy management?
What is the primary focus of Community voting distribution in policy management?
Flashcards are hidden until you start studying
Study Notes
Real Time Responder Roles
- Read Only Analyst includes roles like C.Falcon Analyst and D.Real Time Responder – Active Responder.
- Active Responder enables real-time detection and response actions.
Reducing False Positives
- Reduce false positives for code execution flagged during testing by using a Containment Policy.
- Development work must be stored in a designated file share, "devcode."
Disabling Detections on Hosts
- It's not permissible to disable all detections on individual hosts as it increases risk.
Windows Sensor Update Policies
- There are no "Auto" sensor version update options available for Windows Sensor.
Policy Management in Falcon
- Policy alignment is configured in the General Settings section under the Configuration menu.
- Prevention policies must be aligned with specific host groups for proper deployment.
Operating System Considerations
- Separate sensor update policies for Windows, Mac, and *nix are critical for auditing requirements.
- Each OS may have unique considerations impacting policy deployment and efficacy.
Assigning a Policy to Host Groups
- Assign policies to groups using tag assignments in Host Management to streamline management procedures.
Creating API Clients
- It is essential to immediately save the secret when creating an API client, as it cannot be viewed again.
Reduced Functionality Mode (RFM)
- Hosts may enter Reduced Functionality Mode if a host is offline for over 24 hours due to sensor communication issues.
Sensor Communication Settings
- The CrowdStrike Sensor communicates using TCP port 443 (HTTPS) for secure data transmission.
Obtaining Windows Sensor Installer
- Windows sensor installers are accessible via the Hosts > Sensor Downloads section in the Falcon interface.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.