What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
Which report lists counts of sensors in Reduced Functionality Mode (RFM) for all operating system types, and tracks how long a sensor version will be supported?
What is the purpose of precedence with respect to the Sensor Update policy?
Which option allows you to exclude behavioral detections from the detections page?
Why is it important to know your company's event data retention limits in the Falcon platform?
Which of the following pages provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System?
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20-minute default provisioning window?
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
After agent installation, an agent opens a permanent___connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is terminated.
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
You want to create a detection-only policy. How do you set this up in your policy's settings?
When a Linux host is in Reduced Functionality Mode (RFM) what telemetry and protection is still offered?
You have been provided with a list of 100 hashes that are not malicious but your company has deemed to be inappropriate for work computers. They have asked you to ensure that they are not allowed to run in your environment. You have chosen to use Falcon to do this. Which is the best way to accomplish this?
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
What is the maximum number of patterns that can be added when creating a new exclusion?
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
What may prevent a user from logging into Falcon via single sign-on (SSO)?
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
Where should you look to find the history of the successes and failures for any Falcon Fusion workflows?
How does the Unique Hosts Connecting to Countries Map help an administrator?
When a host belongs to more than one host group, how is sensor update precedence determined?