QUARANTINE FILES Flashcards

1
Q

How to apply options that are required to manage quarantine files?

A

-Enabling Quarantine:
1.Find host’s prevention policy in:
Endpoint Security > Configuration > Prevention Policies

2.Find entry with a type of Next Gen Anti Virus and a category of Quarantine – click Enable All.

3.Recommend setting anti malware prevention levels to Moderate and NOT use other antivirus solutions

-Can review and take action on quarantined directory when monitoring detections

**CS Falcon registers with Windows Security Center, disabling Windows Defender.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Before configuring quarantine what must be done first?

A

-Must FIRST enable quarantining on a prevention policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where are quarantine files located on a Mac host?

A

-Mac Hosts:
/Library/Application Support/CrowdStrike/Falcon/Quarantine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where are quarantine files located on a Windows host?

A

-Windows Hosts:
\Windows\System32\Drivers\CrowdStrike\Quarantine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does the Falcon Sensor only quarantine?

A

-Binary files and PS files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens if you disable quarantine prevention?

A

-Files will be quarantined on host

-Any files previously quarantined files remain quarantined

**Does not apply to: Exploit Mitigation, Ransomware Exploitation Behavior, and Lateral Movement/Credential Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When are quarantined files deleted from the host?

A

-Quarantined files are deleted from host after 30 days

**Can release files to prevent them from being deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When are quarantined files deleted from the cloud?

A

-Files are deleted from the cloud after 90 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If you have files you don’t want to be quarantined, what needs to be done?

A

-An Exclusion needs to be set up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How does the Falcon Sensor quarantine suspicious files?

A

-Falcon sensor can quarantine suspicious files based on prevention policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What happens when a Falcon Sensor detects a suspicious file attempting to run?

A

-The file is encoded, renamed, and moved into a quarantine directory on host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly