Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?
On a Windows host, what is the best command to determine if the sensor is currently running?
Which is the correct order for manually installing a Falcon Package on a macOS system?
You need to export a list of all deletions for a specific Host Name in the last 24 hours. What is the best way to do this?
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however, when applying the new prevention policy this group is not appearing in the list of available groups. What is the most likely issue?
How many "Auto" sensor version update options are available for Windows Sensor Update Policies?
What best describes what happens to detections in the console after clicking "Disable Detections" for a host from within the Host Management page?
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
On the Host management page which filter could be used to quickly identify all devices categorized as a "Workstation" by the Falcon Platform?
Which option allows you to exclude behavioral detections from the detections page?
Which is a filter within the Host setup and management > Host management page?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
You have determined that you have numerous Machine Learning detections in your environment that are false positives. They are caused by a single binary that was custom written by a vendor for you and that binary is running on many endpoints. What is the best way to prevent these in the future?
Which of the following tools developed by Crowdstrike is intended to help with removal of the CrowdStrike Windows Falcon Sensor?
The alignment of a particular prevention policy to one or more host groups can be completed in which of the following locations within Falcon?
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
Which statement describes what is recommended for the Default Sensor Update policy?
An analyst is asked to retrieve an API client secret from a previously generated key. How can they achieve this?
You have created a Sensor Update Policy for the Mac platform. Which other operating system(s) will this policy manage?
Which of the following applies to Custom Blocking Prevention Policy settings?
You have been asked to troubleshoot why Script Based Execution Monitoring (SBEM) is not enabled on a Falcon host. Which report can be used to determine if this is an issue with an old prevention policy?
To enhance your security, you want to detect and block based on a list of domains and IP addresses. How can you use IOC management to help this objective?
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
Which of the following controls the speed in which your sensors will receive automatic sensor updates?
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?