MISC Flashcards

1
Q

What is the Falcon Sensor

A

A lightweight agent you install on each device – when a device has a Falcon sensor installed, we call that device a “host”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a Falcon Sensor do?

A

Each sensor detects and prevents malicious activity on a host, according to policies that you’ll configure later.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Whats are the differences between IOA vs IOC?

A

IOA involves multiple actions over time. IOA = real time, procative

IOC digital evidence that a cyber incident has occurred.

**Intelligence is gathered by security teams in response to speculations of a network breach or during scheduled security audits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the differences between EDR vs NGAV?

A

EDR is detecting after an incident has occurred (IOC/IOA).

NGAV tries to prevent an action from compromising the endpoint.

**AV systems that solely rely on IOC or signature based methods don’t get the job done. Endpoint Detection systems that rely on IOA (Indicators of Attack) are good, as they alert to suspicious activities before a compromise can occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can a host that is not part of a group, get a policy?

A

A host that is NOT in a group CANNOT get assigned a policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How many prevention policies can be created at a time?

A

Can have 100 custom prevention policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many hosts can be issued tags at a time?

A

Can add tags to up to 1000 hosts at a time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many hosts can be added to a static host group at a time?

A

Can add up to 1,000 hosts to a static host group at a time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How to access the Sensor Policy Daily Report

A

Investigate > Sensors > Sensor Policy Daily Report

**Shows update policies/all policies
**Updated Daily

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Sensor ML do?

A

Sensor ML – Identifies/analyzes unknown exe (hosts offline or online)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does Cloud ML do?

A

Cloud ML – Real time malware detection/prevention (Hosts online)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How to see which hosts are in RFM?

A

Executive Summary > Sensors > Sensor Health (see all hosts in RFM)

**Can also go to Investigate (sensor heartbeat events), if value is 2, sensor is in RFM. If value is 0, sensor is not in RFM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define an asset?

A

Asset: Any hardware or virtual machine – a laptop or server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define confidence?

A

Confidence: Likelihood that an unmanaged or unsupported asset is a corporate asset rather than an asset that does not belong to you but is simply nearby (smartphone)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How to disable detections?

A

Host Management > Host > Disable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How to check which sensor version is loaded onto a host?

A

Shows up under host management/sensor health

17
Q

Define a managed asset?

A

Asset that has Falcon sensor installed, also called a host

18
Q

Define a unmanaged asset?

A

Asset that CAN have Falcon sensor installed, but does not

19
Q

Define an unsupported asset?

A

Unsupported Asset: Asset that can’t have a Falcon sensor installed, like a printer

20
Q

what are the steps to Onboard a customer with the Falcon Console

A
  1. Setup Users
  2. Implementation Planning and configuration requirements
  3. Configure SSO
    **Optional
  4. Configure Alerts
  5. Create Phase 1 Prevention Policies
  6. Create Sensor Update Policies
  7. Configure MDM Profiles
    **Used to deploy Mac Sensors
    **optional
  8. Configure OAuth2 for API’s
    **Optional
  9. Install Sensors
  10. Setup Host Groups
  11. Assign Policies to Host Groups
  12. Monitor and Triage Detections
  13. Advance Prevention Policies
  14. Access Support
21
Q

Premium support content in the support portal is only available to which customers?

A

-Express
-Essential
-Elite

22
Q

What can you find in the support portal?

A

-Tech based alerts based on your cloud URL

-Product-based release notes

-Chat
-Upcoming events and webinars

-Service level agreement

23
Q

How to access the support portal?

A

-Falcon menu>support and resources