GROUP CREATION Flashcards
Determine the appropriate group assignment for endpoints. How does this impact the application of policies?
Two types of group assignment for endpoints:
- Dynamic Host Groups
- Static Host Groups
**Defined Manually
What types of policies can be assigned when creating Groups?
- Prevention Policies
- Sensor Update Policies
- USB Device Policies
- Response Policies
- Network Containment Policy
- Mobile Policies
Define precedence when referring to group policies
- determines which policy’s configuration settings are applied to a host when the host is a member of more than one policy
How do Dynamic Host Groups impact the application of policies?
-When the hosts match assignment rule for a dynamic group, its automatically added to the group. When a host no longer matches the assignment rule for the group, it’s automatically removed.
How do Static Host Groups impact the application of policies?
-Static groups are useful for hosts in static environments, such as QA or testing, or for when dynamic group filters are insufficient.
What attributes are Dynamic Host Groups created by?
-Empty upon initial creation. Define filters based on attributes such as grouping tags, IP/CIDR range, OS Version, Active Directory OU, or host name prefix or suffix.
What is the limit for how many Static Host Groups can be added at a time?
-There is a limit of adding 1,000 hosts to a static group at a time.
How do you add hosts to a static group?
Can add hosts to a static group using any of the methods:
- Select hosts using filters in Falcon console
- Manually entering hosts in Falcon console
- Upload a text file containing a list of hosts
When creating Static Host Groups you can add hosts by…
-Hostname or Host ID (AID)
**selection can NOT be changed later
Where are polices configured
Falcon Console > Configuration
What policy describes what kind of activity isn’t allowed on a host?
-Prevention Policies
Which policy describes configuring USB devices, review device control dashboards, and USB violations?
-USB Device Policy
How are policies assigned?
-Policies are assigned to hosts within Host Groups
**Available prevention settings vary by platform
When configuring a USB Device policy, what are the policy configuration options?
Policy Options (3):
-Monitor and Enforce
-Monitor Only
-Off
Certain activity will trigger detections and preventions on hosts that have a prevention policy configured, where can you monitor these actions?
Falcon Console > Activities Application
Describe workflows
Workflows help streamline analyst operations by creating automatic actions that precisely define actions you want Falcon to perform in response to incidents, detections, policies, cloud security findings, and updates made by users.