GROUP CREATION Flashcards

1
Q

Determine the appropriate group assignment for endpoints. How does this impact the application of policies?

A

Two types of group assignment for endpoints:

  • Dynamic Host Groups
  • Static Host Groups
    **Defined Manually
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of policies can be assigned when creating Groups?

A
  • Prevention Policies
  • Sensor Update Policies
  • USB Device Policies
  • Response Policies
  • Network Containment Policy
  • Mobile Policies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define precedence when referring to group policies

A
  • determines which policy’s configuration settings are applied to a host when the host is a member of more than one policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do Dynamic Host Groups impact the application of policies?

A

-When the hosts match assignment rule for a dynamic group, its automatically added to the group. When a host no longer matches the assignment rule for the group, it’s automatically removed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do Static Host Groups impact the application of policies?

A

-Static groups are useful for hosts in static environments, such as QA or testing, or for when dynamic group filters are insufficient.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What attributes are Dynamic Host Groups created by?

A

-Empty upon initial creation. Define filters based on attributes such as grouping tags, IP/CIDR range, OS Version, Active Directory OU, or host name prefix or suffix.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the limit for how many Static Host Groups can be added at a time?

A

-There is a limit of adding 1,000 hosts to a static group at a time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you add hosts to a static group?

A

Can add hosts to a static group using any of the methods:
- Select hosts using filters in Falcon console
- Manually entering hosts in Falcon console
- Upload a text file containing a list of hosts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When creating Static Host Groups you can add hosts by…

A

-Hostname or Host ID (AID)
**selection can NOT be changed later

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where are polices configured

A

Falcon Console > Configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What policy describes what kind of activity isn’t allowed on a host?

A

-Prevention Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which policy describes configuring USB devices, review device control dashboards, and USB violations?

A

-USB Device Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How are policies assigned?

A

-Policies are assigned to hosts within Host Groups
**Available prevention settings vary by platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When configuring a USB Device policy, what are the policy configuration options?

A

Policy Options (3):
-Monitor and Enforce
-Monitor Only
-Off

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Certain activity will trigger detections and preventions on hosts that have a prevention policy configured, where can you monitor these actions?

A

Falcon Console > Activities Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe workflows

A

Workflows help streamline analyst operations by creating automatic actions that precisely define actions you want Falcon to perform in response to incidents, detections, policies, cloud security findings, and updates made by users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Describe the capabilities in creating workflows

A
  • Can send out Slack notifications based on cloud container image assessment findings
  • Generate ServiceNow incident tickets when high severity vulnerabilities are detected
  • Run RTR scripts to manage affected hosts when incidents are reported

-Use Triggers (Falcon detects a Vulnerability)

  • Set Conditions (Vulnerability has a severity of “Critical”)

-Actions (create a ServiceNow Incident)

-Else/Else If Statements: Use Conditional statements to set up multiple workflow branches

-And Statements: Group multiple conditions within a single workflow branch

-Parallel actions and conditions: Create independent branches of actions and conditions within a single workflow

-Sequential Actions: Add Actions to be performed in a specific order within a workflow branch

18
Q

Define policies with different precedence’s to resolve conflicts.

A

When faced with conflict, Falcon Cloud will apply the policy with the higher precedence

19
Q

Explain what happens to a host that is not part of any groups or the groups it belongs to has no policy assigned?

A

The host is automatically assigned to the default policy

20
Q

Do all OS operate off the same policies?

A

No. Different Prevention policies for different Operating Systems

21
Q

Can host groups be assigned one or more policies?

A

-Yes
**The policy with the highest order precedence (1) gets applied

22
Q

Can a single host belong to one or more host groups?

A

-Yes. A single host can fall within multiple groups with each of those groups targeting different policies

**Allows the scalability to be as simple or complex as needed

23
Q

What happens with Dynamic Groups when a new sensor is installed?

A

-With dynamic groups, a newly-installed sensor inherits relevant groups and applies policy with highest precedence to the host

**provides host with its initial policy settings.

24
Q

If a hosts policy changes, what also changes?

A

-The setting applied to the host also changes. Changing aspects of the host can change its group and therefore change its active policy.

25
Q

What is the highest-ranking precedence that can be applied to host

A

-1 is the highest precedence

26
Q

On a host, which policy gets applied?

A

-The policy with the highest-ranking precedence is applied and active (1 is the highest precedence)

**If something changes with that high-ranking policy, then the next highest-ranking policy gets applied and becomes active.

27
Q

What do host groups allow you to do?

A

-assign policy settings
-upgrade schedules
-file exclusions

27
Q

Define a dynamic host group?

A

-Hosts defined by attributes that when matched are added and removed automatically
**most flexible and recommended to use in most cases

28
Q

Define a static host group?

A

Hosts added and removed manually
**can be added by adding a list of hostnames or selecting a list of names in the Falcon Console

29
Q

How to create a dynamic host group?

A

Host setup and Management>manage endpoints> Host groups> add new group> name and description>select group type (Dynamic)>add group

Click edit to assign rule filters>input criteria in filter bar> save

30
Q

How to configure a static host group?

A

Host setup and Management>manage endpoints> Host groups> add new group> name and description>select group type (static)>add group> add hosts

Click checkbox to select hosts> add>add host> done

31
Q

Once a host is added to a group…

A

It cannot be changed

32
Q

What circumstances can impact the hosts in a dynamic group?

A

-Policy precedence
-Changing aspects of the host
-unplanned changes to a host

33
Q

What is the timelapse between when you create a dynamic rule and when it gets applied to hosts

A

40 mins

33
Q

What is the timelapse between when you create a dynamic rule and when it gets applied to hosts

A

40 mins

34
Q

Why is it recommended to use Dynamic host groups vs static groups?

A

using static groups can result in:

-hosts changing security settings if the hostname is changed
-host duplication in the falcon console

35
Q

Can a host group be part of more than one assigned policy?

A

-No. After a host group is assigned a policy, that host group no longer appears in the list available groups

36
Q

How to assign a host group to a prevention policy?

A

Falcon main menu> endpoint security>configure> prevention policies>edit>assigned host groups tab> add groups to policy> select groups> click add groups to policy

37
Q

How to assign a host group to a sensor update policy?

A

Falcon main menu> host setup and management> deploy>host sensor policies edit>assigned host groups tab> add groups to policy> select groups> click add groups to policy

38
Q

How to ensure the proper settings are applied and that the active policy is verified?

A

-Check the host group
-check individual host

39
Q

How to review a groups policy precedence?

A

Falcon main menu>endpoint security>configure> prevention polices>view