HOST MANAGEMENT Flashcards

1
Q

How might filtering be used in the Host Management Page?

A
  • Use Filter Bar at the top to search for a specific host

-Click Default Filters to view a more targeted list

-Choose columns that appear on Host Management page by clicking column selection button on right side of screen.

  • Use filters to filter down to a specific type of host or category, then assign those hosts to dynamic or static groups accordingly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How to disable detections for a host?

A
  • Click Disable Detections

**Helpful for users that want to set up hosts to test detections in Falcon Console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain the effect of disabling detections on a host

A
  • Feature only suppresses detections for the host. Feature does not disable sensor or interfere with sensor’s ability to protect the host.
  • Sensor continues to operate normally except detections for host do not appear in Activity > Detections feed
  • Activity related to hosts is still factored into Activity > Incidents

-Configurations for prevention policy, prevention hash rules, exclusion rules, etc that are applied to a host are still processed normally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain the impact of reduced functionality mode (RFM).

A

RFM: Safe mode for the sensor that prevents compatibility issues if the host’s kernel is uncertified.

  • Sensors in RFM temporarily unhook from some kernel elements – without those elements, some detection patterns and a small # of preventions will not be triggered
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How to find hosts in RFM?

A

-Falcon Console> Dashboards> Executive Summary lists a count of sensors in RFM

-Falcon Console> Investigate can see SensorHeartBeat events generated by sensor, contains value SensorStateBitMap_Decimal – use value to see if sensor is in RFM.

-Endpoint Activity Monitoring (EAM) queries to report list of hosts in RFM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How to find inactive sensors

A
  • Accounts Overview dashboard – review accounts last logged in more than 2 weeks ago. Click a bar in the chart to open a table of accounts that successfully logged in within that time frame.

**Users with Falcon Admin role can clean up inactive or duplicate hosts by deleting them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long are inactive sensors retained in order to define an organization’s data backup plan?

A
  • Inactive endpoints will automatically removed from the CrowdStrike cloud console after 45 days of inactivity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which reports are used when reporting on information relating to a host?

A
  • Scheduled Reports
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain the importance of understanding a company’s insight data retention timeframe

A

-Falcon Insights
**Tools to better evaluate the risks and threats to which network is exposed, enhancing the organizational security posture

-Lack of data retention
**Cannot look back in time to investigate incase of incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are some examples of Host Management groups created based off filters?

A

Can create Host Management groups based off filters such as:

-Platform
-OS
-OU
-Site
-Type
-Containment Status
-Grouping Tags

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Explain what effect the Falcon console takes when disabling detections on a host

A

Falcon Console Impact:

-Detections for host are removed from console immediately

**No new detections will display in console going forward unless detections are enabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Explain what effect the API takes when disabling detections on a host

A

API Impact:

-DetectionSummaryEvent stops being sent to the Streaming API for that host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Explain what effect the Event Search takes when disabling detections on a host

A

Event Search Impact:

-After disabling detections, data for all existing detections prior to disabling detections will still be in Event Search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Why might RFM be used on a Windows host?

A

Windows:

-RFM happens around security updates
**if security updates are applied within the first 48 hours machines will go into RFM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the difference between a Windows and Linux host entering RFM?

A

Windows and Linux sensors can enter RFM, but RFM behaves differently on each platform:

-Windows sensor enters RFM, it still actively monitors your system, reports events, and triggers detections, but at a reduced capacity

-Linux is full STOP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What use value does the host have to have to show the sensor is in RFM?

A

-If value is 2, sensor is in RFM

17
Q

What use value does the host have to have to show the sensor is NOT in RFM?

A
  • If value is 0, sensor is not in RFM
18
Q

Use EAM query to verify that sensors have….

A

Use EAM query to verify sensors have:
-Current OS Feature Manager (OSFM) certification file

19
Q

Where are OSFM certification files located on the host?

A

If you’d prefer to verify file version on host:

-OSFM cert files are located in CrowdStrike Directory> SystemRoot> CrowdStrike etc.

20
Q

How are inactive hosts identified?

A
  • Inactive hosts are identified by their “Last Seen” time
21
Q

When does a host become inactive?

A

-Host becomes inactive when its sensor doesn’t send a heartbeat back to the cloud for 2 minutes

22
Q

Why are Scheduled Reports significant?

A

–Provides automatic, recurring updates of data that matters the most to you.

-Download and share scheduled reports, and receive a notification each time a new report is available.

-Can get a weekly summary of hosts in environment, count of hosts with critical vulnerabilities.

-Monthly snapshot of Executive Summary dashboard

23
Q

What roles are required to generate Scheduled Reports?

A

Roles required:

-Scheduled Report Administrator

-Falcon Administrator and Intel Admin

-Scheduled Report Analyst

**All other roles can create scheduled reports, view/manage scheduled reports, and download/delete reports generated from scheduled reports.

24
Q

What are the capabilities that Scheduled Reports generates?

A

-Schedule automated generation of Private/Shared/Preset Dashboards
**Can also schedule reports with data from Host Management page.

-Can select a start/end date for reports
** A date to begin running scheduled report and a date to stop running report.

-Can run reports daily, weekly, or monthly

-Can send new generated report notifications to individual users by email or to groups of users through Slack, PagerDuty, Microsoft Teams, or Webhook.

-Can use dashboards to view – active sensor count, cloud sensor hourly usage average, hourly cloud usage, sensor usage by cloud, and cloud workload hours for a specified time period.

25
Q

Why might RFM be used for a Linux host?

A

Linux

-RFM happens w/ unsupported or incompatible kernel versions
**if kernel is updated within the first 10 days machines will go into RFM

26
Q

How does a Linux host in RFM return to full functionality?

A

-Update the kernel when a new one is released to stay on supported Linux OS and kernels

27
Q

How does a Windows host in RFM return to full functionality?

A

-Security updates will not affect your machines applied to machines after 48 hours
**CS certifies compatibility and releases it through the cloud

27
Q

How does a Windows host in RFM return to full functionality?

A

-Security updates will not affect your machines applied to machines after 48 hours
**CS certifies compatibility and releases it through the cloud

28
Q

What CS cloud version are most US customers connected to?

A

-US-1
** ts01-b.cloudsink.netlfodown01-b.cloudsink.net

29
Q

What CS cloud version are EU customers connected to?

A

-EU-1
**ts01-lanner-lion.cloudsink.netlfodown01-lanner-lion.cloudsink.net

30
Q

What CS cloud version are most GOV/SLED customers connected to?

A

-US-GOV-1
** ts01-laggar-gcw.cloudsink.netlfodown01-laggar-gcw.cloudsink.net

31
Q

What CS cloud version are US customers connected to as a secondary?

A

-US-2
** ts01-gyr-maverick.cloudsink.netlfodown01-gyr-maverick.cloudsink.net