OB SLIDE PRESENTATION QUESTIONS Flashcards
Can we modify the Playbook for Detection Responses?
(customer that doesn’t care about Warranty so asks to make everything custom)
?
Why may Time to Live vary?
?
What is OverWatch?
CrowdStrikes Threat Hunting Team. Provides 24/7 support to stop hidden and advanced attacks.
RFM covered by Warranty?
If i have some in Cautious would that mean my entire account has no warranty
yes,
Deployment help?
deployment is on your and your teams play, however if you run into trouble then we can create a support ticket
What is System Assignment
?
How long should I be in Cautious policy?
the less amount as time as possible is recommended
How long does FC take to go live?
1 week
How can I provide you my current exclusion list from Symantec?
What happens when my email gets compromised?
Will keep calling until someone answers for Critical escalations?
Yes. Everyone that will be contacted will be in order of precedence by the Appendix B document.
SA will monitor the RFM?
?
What’s a “Incident” ?
swat team vs detectives. we prevent incidents in real time and not going back to historically analyze any items and
Call for Only “Critical Detection? For every Critical Detection”?
?