What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
Which report can assist in determining the appropriate Machine Learning levels to set in a Prevention Policy?
An analyst has reported they are not receiving workflow triggered notifications in the past few days. Where should you first check for potential failures?
Your organization has a set of servers that are not allowed to be accessed remotely, including via Real Time Response (RTR). You already have these servers in their own Falcon host group. What is the next step to disable RTR only on these hosts?
What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?
What should be disabled on firewalls so that the sensor's man-in-the-middle attack protection works properly?
What would be the most appropriate action to take if you wanted to prevent a folder from being uploaded to the cloud without disabling uploads globally?
Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?
What is the most common cause of a Windows Sensor entering Reduced Functionality Mode (RFM)?
You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
After agent installation, an agent opens a permanent___connection over port 443 and keeps that connection open until the endpoint is turned off or the network connection is terminated.
Which of the following prevention policy settings monitors contents of scripts and shells for execution of malicious content on compatible operating systems?
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
What best describes the relationship between Sensor Update policies and Operating Systems?
Which of the follow should be used with extreme caution because it may introduce additional security risks such as malware or other attacks which would not be recorded, detected, or prevented based on the exclusion syntax?
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
When a Linux host is in Reduced Functionality Mode (RFM) what telemetry and protection is still offered?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
When creating an API client, which of the following must be saved immediately since it cannot be viewed again after the client is created?
In order to exercise manual control over the sensor upgrade process, as well as prevent unauthorized users from uninstalling or upgrading the sensor, which settings in the Sensor Update Policy would meet this criteria?
Which of the following can a Falcon Administrator edit in an existing user's profile?