DASHBOARD Flashcards

1
Q

What does the Endpoint Security module do?

A

-Provides info about incidents, detection & prevention activities found by Falcon sensors

**Detections are triggered from prevention policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the Cloud Security module do?

A

Registers cloud accounts and sets cloud policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does Identity Protection module do?

A

-Monitors network traffic to build user behavioral profiles and identifies unusual behavior

-Enables frictionless Zero Trust Security w/ real-time threat prevention and IT policy enforcement

*Falcon identity threat detection or falcon identity threat protection subscription needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the spotlight module do?

A

-Identifies vulnerabilities on Windows and Linux hosts
Helps the team proactively patch vulnerable hosts, reducing team falcons attack surface and lowering risk profile

*Falcon insight add on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does the discover module do?

A

-Provides deep visibility into the apps used in your environment
Information helps you determine:
-whether or not approved apps are being used
-which device may not have a sensor installed on them
-which users have administrator access

*falcon insight add-on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does the FileVantage module do?

A

-Helps with industry compliance

*May need to modify host groups to create file integrity policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does the Threat Intelligence module do?

A

-provides reports, feeds, alerts, and data to subscribers of CS intelligence products (Falcon X)

*Falcon prevent add on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the investigate module do?

A

-gives access to several reports and queries. Allows a deeper dive into event data that is captured by the sensor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the dashboards & reports module do?

A

-gives a graphical view into data sets that matter most

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Host setup and management module do?

A

-set up and manages the orgs defenses w/ host groups, sensor, and response policies, user, and user permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the crowdstrike store module do?

A

-A marketplace that allows you to try out new apps in your environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the audit logs module do?

A

-audits various activites within the falcon console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which icon allows you to choose a “Stay signed in” option to stay logged into the activity dashboard until the borrower is restarted?

A

-Settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the Support and resources module do?

A

-P rovides access to all CS product documentation and a variety of tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

This module can be used as an auditing tool to find gaps in defenses that may need new policies..

A

Endpoint Security module

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

This module can be used to install patches for vulnerabilities on your hosts with the appropriate roles

A

spotlight module

17
Q

This module can be used to learn how policies need to be modified by finding assets that are unmanaged or unsupported

A

discover module

18
Q

This module can set up prevention policies that automatically submit files to falcon X

A

threat intelligence

19
Q

This module can be used to conduct proactive hunting and as an auditing tool

A

investigate module

20
Q

Use this module to setup sensors, create workflows using falcon fusion, and manage installation tokens

A

Host setup and management module

21
Q

This module can use the executive summary dashboard to find sensors that have become inactive

A

dashboards & reports module

22
Q

Use this module to review logs, audit activity, and fine tune prevention policy settings

A

audit logs module

23
Q

As a falcon admin role, you can use this module to create, view, edit API clients and keys and can access the sensor unintaller

A

Support and resources module

24
Q

You need to create new users, host groups and prevention policies to protect your environment. Which 2 sections will you use to complete these tasks?

A

-endpoint security X

-Host setup and managementX