The Falcon sensor uses certificate pinning to defend against man-in-the-middle attacks. Which statement is TRUE concerning Falcon sensor certificate validation?
A. SSL inspection should be configured to occur on all Falcon traffic
B. Some network configurations, such as deep packet inspection, interfere with certificate validation
C. HTTPS interception should be enabled to proceed with certificate validation
D. Common sources of interference with certificate pinning include protocol race conditions and resource contention
Which of the following is an effective Custom IOA rule pattern to kill any process attempting to access www.badguydomain.com?
A. .*badguydomain.com.*
B. \Device\HarddiskVolume2\*.exe -SingleArgument www.badguydomain.com /kill
C. badguydomain\.com.*
D. Custom IOA rules cannot be created for domains
How does the Unique Hosts Connecting to Countries Map help an administrator?
A. It highlights countries with known malware
B. It helps visualize global network communication
C. It identifies connections containing threats
D. It displays intrusions from foreign countries
What is the purpose of the Machine-Learning Prevention Monitoring Report?
A. It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
B. It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious
C. It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
D. It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
What is the maximum number of patterns that can be added when creating a new exclusion?
A. 10
B. 0
C. 1
D. 5
When performing targeted filtering for a host on the Host Management Page, which filter bar attribute is NOT case-sensitive?
A. Username
B. Model
C. Domain
D. Hostname
Which of the following is TRUE regarding disabling detections for a host?
A. After disabling detections, the host will operate in Reduced Functionality Mode (RFM) until detections are enabled
B. After disabling detections, the data for all existing detections prior to disabling detections is removed from the Event Search
C. The DetectionSummaryEvent continues being sent to the Streaming API for that host
D. The detections for that host are removed from the console immediately. No new detections will display in the console going forward unless detections are enabled
Under the "Next-Gen Antivirus: Cloud Machine Learning" setting there are two categories, one of them is "Cloud Anti-Malware" and the other is:
A. Adware and PUP
B. Advanced Machine Learning
C. Sensor Anti-Malware
D. Execution Blocking
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
A. Use the Sensor Report to filter to the specific endpoint
B. Use the Investigate > Host Search to filter to the specific endpoint
C. Use Host Management to select the desired endpoint. The agent version will be listed in the columns and details
D. From a command line, run the sc query csagent -version command
What information does the API Audit Trail Report provide?
A. A list of analyst login activity
B. A list of specific changes to prevention policy
C. A list of actions taken via Falcon OAuth2-based APIs
D. A list of newly added hosts