Which of the following tools developed by Crowdstrike is intended to help with removal of the CrowdStrike Windows Falcon Sensor?
What information does the API Audit Trail Report provide?
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
On which page of the Falcon console would you create sensor groups?
How can you find a list of hosts that have not communicated with the CrowdStrike Cloud in the last 30 days?
Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
A Falcon Administrator is trying to use Real-Time Response to start a session with a host that has a sensor installed but they are unable to connect. What is the most likely cause?
You are evaluating the most appropriate Prevention Policy Machine Learning slider settings for your environment. In your testing phase, you configure the Detection slider as Aggressive. After running the sensor with this configuration for 1 week of testing, which Audit report should you review to determine the best Machine Learning slider settings for your organization?
Which of the following controls the speed in which your sensors will receive automatic sensor updates?
Which of the following is a valid step when troubleshooting sensor installation failure?
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
What statement is TRUE about managing a user's role?
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
When editing an existing IOA exclusion, what can NOT be edited?
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
You are attempting to install the Falcon sensor on a host with a slow Internet connection and the installation fails after 20 minutes. Which of the following parameters can be used to override the 20-minute default provisioning window?
How do you assign a policy to a specific group of hosts?
When configuring a specific prevention policy, the admin can align the policy to two different types of groups, Host Groups and which other?
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
Which of the following pages provides a count of sensors in Reduced Functionality Mode (RFM) by Operating System?
Where do you obtain the Windows sensor installer for CrowdStrike Falcon?
A sensor that has not contacted the Falcon cloud will be automatically deleted from the hosts list after how many days?
What command should be run to verify if a Windows sensor is running?
What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?
Custom IOA rules are defined using which syntax?
Once an exclusion is saved, what can be edited in the future?
Which of the following roles allows a Falcon user to create Real Time Response Custom Scripts?
Which of the following uses Regex to create a detection or take a preventative action?
You have a new patch server that should be reachable while hosts in your environment are network contained. The server's IP address is static and does not change. Which of the following is the best approach to updating the Containment Policy to allow this?
Which of the following is NOT an available action for an API Client?
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
How many days will an inactive host remain visible within the Host Management or Trash pages?
Which option best describes the general process Whereinstallation of the Falcon Sensor on MacOS?
When a user initiates a sensor installs, where can the logs be found?
You want the Falcon Cloud to push out sensor version changes but you also want to manually control when the sensor version is upgraded or downgraded. In the Sensor Update policy, which is the best Sensor version option to achieve these requirements?
What is the purpose of the Default Sensor Policy?
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?
Which of the following Machine Learning (ML) sliders will only detect or prevent high confidence malicious items?
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?
Why do Sensor Update policies need to be configured for each OS (Windows, Mac, Linux)?
In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor Update Policy would meet this criteria?
What may prevent a user from logging into Falcon via single sign-on (SSO)?
When a host is placed in Network Containment, which of the following is TRUE?