Falcon Prevent Flashcards
ML on Sensor - Benefits + Questions
Benefits: Prevents new and old malware strains, small footprint on machin, sensor is no greater the 25 MB, less then 1% cpu
Question: What AV do you use? What other security agents do you have? how do you computers perform when AV is running
Block Known Bad - Benefits + Questions
Benefits: No .DAT = decrease the footprint on endpoint, still protected by the crowd of intel
Questions: Does your AV use signatures, does it require signature updates?
Exploit Mitigation - Benefits + Questions
Benefit: Helps stop know and zero day attack ( unknown exploit in the wild that exposes a vulnerability in software and can cause issues before anyone knows what happenend)
Question: How are you mitigating against potential exploits today
Indicator of Attacks ( IOA )