Which of the following tools developed by Crowdstrike is intended to help with removal of the CrowdStrike Windows Falcon Sensor?
What best describes what happens to detections in the console after clicking "Enable Detections" for a host which previously had its detections disabled?
Which of the following is NOT a way to determine the sensor version installed on a specific endpoint?
Which option allows you to exclude behavioral detections from the detections page?
Which exclusion pattern will prevent detections on a file at C:\Program Files\My Program\My Files\program.exe?
When creating a Host Group for all Workstations in an environment, what is the best method to ensure all workstation hosts are added to the group?
You notice there are multiple Windows hosts in Reduced functionality mode (RFM). What is the most likely culprit causing these hosts to be in RFM?
Which is the correct order for manually installing a Falcon Package on a macOS system?
When uninstalling a sensor, which of the following is required if the 'Uninstall and maintenance protection' setting is enabled within the Sensor Update Policies?
While a host is Network contained, you need to allow the host to access internal network resources on specific IP addresses to perform patching and remediation. Which configuration would you choose?
You have an existing workflow that is triggered on a critical detection that sends an email to the escalation team. Your CISO has asked to also be notified via email with a customized message. What is the best way to update the workflow?
The Logon Activities Report includes all of the following information for a particular user EXCEPT __________.
Which of the following best describes what the Uninstall and Maintenance Protection setting controls within your Sensor Update Policy?
Which report lists counts of sensors in Reduced Functionality Mode (RFM) for all operating system types, and tracks how long a sensor version will be supported?
After Network Containing a host, your Incident Response team states they are unable to remotely connect to the host. Which of the following would need to be configured to allow remote connections from specified IP's?
You are beginning the rollout of the Falcon Sensor for the first time side-by-side with your existing security solution. You need to configure the Machine Learning levels of the Prevention Policy so it does not interfere with existing solutions during the testing phase. What settings do you choose?
You have been asked to troubleshoot why Script Based Execution Monitoring (SBEM) is not enabled on a Falcon host. Which report can be used to determine if this is an issue with an old prevention policy?
When creating a custom IOA for a specific domain, which syntax would be best for detecting or preventing on all subdomains as well?
Which port and protocol does the sensor use to communicate with the CrowdStrike Cloud?
What model is used to create workflows that would allow you to create custom notifications based on particular events which occur in the Falcon platform?
You want to create a detection-only policy. How do you set this up in your policy's settings?
When a Linux host is in Reduced Functionality Mode (RFM) what telemetry and protection is still offered?
A Falcon Administrator is trying to use Real-Time Response to start a session with a host that has a sensor installed but they are unable to connect. What is the most likely cause?
What is likely the reason your Windows host would be in Reduced Functionality Mode (RFM)?
The Falcon Administrator has created a new prevention policy to apply to the "Servers" group; however, when applying the new prevention policy this group is not appearing in the list of available groups. What is the most likely issue?
What best describes the relationship between Sensor Update policies and Operating Systems?