SENSOR DEPLOYMENT Flashcards

1
Q

What are the Windows OS requirements prior to installing the Falcon Sensor?

A

OS Requirements:

-Windows 7, 8.1, 10, 11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the network protocols needed prior to installing the Falcon Sensor?

A

Network Protocols (2):

  • Falcon requires TLS 1.2 to communicate with CrowdStrike Cloud.
  • Requires Logon local audit policy to be “success and failure”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where in the Falcon console do you copy the CID/ Checksum?

A

-Copy customer ID checksum from Hosts > Sensor Downloads – It is Alphanumeric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to uninstall a Falcon Sensor on Windows?

A

Windows: Control Panel or CMD line

-Control Panel
Control Panel > uninstall a program > Choose Crowdstrike Windows Sensor

-CMD Line
** Download CSUinstallTool from Tool Downloads.

CMD w/ admin priv > CSUninstallTool.exe /quiet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What default policies are required in order to prepare workloads for the Falcon Sensor?

A
  • Requires Local audit policy to have setting of “Success and Failure”**If actual policy setting does not match setting, sensor changes it
    to match.
  • Registry key DNScache/Type must be set to 0x00000020 Microsoft default value.
    **Windows Defender should be disabled
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What appropriate settings are needed to install a Falcon Sensor on Windows?

A

-Needs to be able to communicate with CrowdStrike FQDN and IP – may need networking to allow list and not block communication

  • Needs to have communication over port 443 with the CS Cloud during installation and ongoing.
  • Needs to communicate utilizing TLS 1.2 with the CS Cloud
  • Disable packet inspection or similar network configurations (HTTPS or TLS Inspection)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What appropriate settings are needed to install a Falcon Sensor on Mac?

A

Needs to have elevated privileges in order to install the sensor on Mac

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What appropriate settings are needed to install a Falcon Sensor on Linux ?

A

-Needs to be Kernel specific to run the Falcon Sensor

**If a kernel is not listed in the guide, the sensor will still install, but will run in reduced functionality mode (RFM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How to do you apply additional options for images/VDI’s, tokens, and tags?

A

-Put image template system into read/write mode
- Install Falcon sensor using the VDI=1 parameter
- Complete all steps required to generalize VM template
– Install Falcon using NO_START=1 Parameter.

**After installation, sensor does not attempt to communicate with
CS Cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What issues can occur with the basic configuration requirements of the system environment or Falcon components?

A

-Host can’t communicate with CS Cloud

-The Falcon Sensor requires the host to have their CA certs in Trust Root CA store
**Check whether certs are present, download/import them if needed

-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to troubleshoot a Falcon Sensor installation on a Windows host?

A

-Check the Channel Files – additional sensor instructions that provide updated settings for policies, allowlists/blocklists, detection exclusions, support for new OS patches and more.

-Verify sensor is running: cmd admin priv > sc.exe query csagent

-verify sensor is connected to the CS Cloud: cmd > netstat.exe -f

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How to troubleshoot a Falcon Sensor installation on a Linux host?

A

-Install dependent packages: apt-get -f install

-Verify Sensor is Running: ps -e | grep -e falcon-sensor

-Verify sensor is connected to the CS Cloud: sudo netstat -tapn | grep galcon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How to troubleshoot a Falcon Sensor installation on a Mac host?

A

Verify sensor is running and connected to the CS Cloud:

-sudo /Applications/Falcon.app/Contents/Resources/falconctl stats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Conduct root cause analysis related to system/ user issues

A

-DigicerthighassuranceRootCA cert must be in trusted Root CA Store

**Need Root Access to Host to do that

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the technical requirements required prior to installing the Falcon Sensor?

A

Services required:

-LMHosts
-Network Store Interface (NSI)
-Windows Base Filtering Engine (WBF)
-Windows Power Service (Power)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Prior to installing the Falcon Sensor, Falcon’s NGAV setting needs to have…..

A

-Windows Defender DISABLED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When happens when you install a sensor in a VDI environment?

A

When you install sensor in a VDI environment:

  • Sensor runs from a shared, read only OS image.

-CS Cloud assigns a unique AID based on host’s FQDN and other characteristics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Falcon sensor will install, but not run if any of the following services are disabled or stopped?

A

Sensor can install but not run if any of the following services that are disabled or stopped:
- LMHosts
- Windows Base Filtering engine
- DHCP Client
- DNS Client

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

LM Hosts may be disabled on the host if the following service is disabled?

A

-TCP/IP NetBIOS Helper service is disabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

How to verify the Falcon Sensor is connected to the CS Cloud?

A

Verify the sensor is connected to the CS Cloud (2 ways):
-Falcon Console – Use Sensor Report

   -Host – cmd admin priv > run
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

If host can’t connect to CS Cloud, check if…..

A

If Host can’t connect to CS Cloud, check if:

-Host can connect to internet,
-Verify proxy configuration
-Configure endpoint FW to permit traffic to/from Falcon sensor
-Verify that the host’s LMHost service is enabled
-Verify host trusts CS CA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

The Falcon Sensor requires host to have which CA certs in Trust Root CA store?

A

Falcon sensor requires host to have (2):
-DigiCertHigh AssurancerootCA

-DigiCertAssuredIDRootCA

**Both certs need to be in Trust Root CA Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What steps are taken in order to add CS CA’s are present on host?

A

-Microsoft Management Console > follow Microsoft documentation to enable Certificates snap-in.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What happens when the Falcon Sensor installs on a Windows Host?

A

-Sensor installer uses standard Windows installer mechanism to set up Falcon’s sensor files and registry keys.

-If using installation tokens, CS cloud checks installer’s token

-Sensor contacts CS Cloud, which assigns the AID (Agent ID) for the host.

25
Q

What should be examined when conducting a root cause analysis related to system/ user issues?

A
  • Must run installation with admin privileges
  • Look for CID being incorrect
  • Windows BFE can not be present/damaged
  • GUID of previous install can’t be removed
26
Q

What is the most common problem that occurs when installing the Falcon Sensor?

A

Most common problem:
-Communication between host and the CS Cloud

27
Q

What is needed to whitelist CrowdStrike Endpoints?

A

Need to whitelist CrowdStrike Endpoints:
- Ensure Port 443 is open for 2 endpoints

  • Cert Pinning/SSL Inspection must be DISABLED – all Falcon
    traffic must be whitelisted from SSL Inspection.
28
Q

If the windows host is using a proxy, what other service needs to be available?

A

-Win HTTP Auto Proxy

29
Q

If the windows host is using Web Proxy Automatic Discover, what service also needs to be running?

A

-DHCP

30
Q

What port does the host need to be able to the CS Cloud on?

A

-Hosts must be connected to CS Cloud on port 443 during
installation
**must allow traffic to and from CS Cloud FQDNs/IP Addresses

31
Q

How long does it take for a host to connect to the CS cloud through installation?

A

-10 minutes

**When the sensor cant connect to the cloud, it also takes 10 mins to it to re-establish a connection

32
Q

what is the PS command to disable windows defender?

A

Set-MpPreference -DisableRealtimeMonitoring $True

33
Q

What happens the second time if the sensor cant connect to the cloud?

A

-The sensor will uninstall from the system & exit the installer

34
Q

What is the command to determine the Linux kernel version?

A

uname -r

35
Q

What does the falcon sensor use to defend against man-in-the middle attacks?

A

Certificate pinning

36
Q

When the sensor is installed, the sensor is configured with what 2 policies?

A
  • prevention policy

-sensor update policy

37
Q

What are sensor tags?

A

enable the user to categorize sensor enabled hosts by location, environment, purpose, etc

**can be assigned after confirmation that falcon sensor has been installed

38
Q

What does the sensor is installed what connection stays permanently open?

A

-After agent installation, agent opens permanent TLS
connection over port 443 and keeps connection open until endpoint is turned off or if the network connection is
terminated.

**Might need allow TLS Traffic on port 443
between internal network and cloud’s network addresses

38
Q

What does the sensor is installed what connection stays permanently open?

A

-After agent installation, agent opens permanent TLS
connection over port 443 and keeps connection open until endpoint is turned off or if the network connection is
terminated.

**Might need allow TLS Traffic on port 443
between internal network and cloud’s network addresses

39
Q

Where do customized sensor tags show up in the falcon console?

A

-falcon menu> host management

40
Q

Which 2 methods can the Falcon Sensor be installed on a Windows host?

A

Can install Falcon sensor for Windows using either

-GUI
-automated command line installation

41
Q

what commands installs the sensor on a linux host?

A

sudo /opt/crowdstrike/falconCH -s –cid=<CID></CID>

42
Q

what commands installs the sensor on a linux host?

A

sudo /opt/crowdstrike/falconCH -s –cid=<CID></CID>

43
Q

What adds support for Linux kernels through channel files w/out requiring a sensor update?

A

Zero Touch Linux (ZTL)

44
Q

Where on the Falcon Console can you download the sensor?

A

-Hosts > Sensor Downloads

45
Q

What is required to deploy falcon to Mac systems?

A

-MDM (mobile device management) solution to distribute the profile to endpoints prior to the sensor deployment process

46
Q

What happens if you don’t use an MDM solution?

A

-multiple confirmations occur on the host and must manually be approved

47
Q

How to use an MDM to configure profiles?

A

-Falcon menu>host setup and management>deploy>sensor downloads>locate sensor installer for Mac>click download>copy customer CCID or checksum

Cmd line> sudo installer -verboseR -package <installer_filename> -target />enter admin creds>run cmd falconctl</installer_filename>

48
Q

Which methods run the sensor installer on a Mac device?

A

-double click the .pkg file
-cmd line
sudo installer -verboseR -package <installer_filename> -target /</installer_filename>

49
Q

How does the falcon sensor stop breaches?

A

Unifies:
-Next gen antivirus
-Endpoint protection and response (EDR)
-Managed threat hunting
-Threat intelligence automation using a single lightweight sensor

50
Q

How long should sensor installation take to install sensors on all hosts?

A

-45 days

51
Q

How to install sensors automatically?

A

Falcon main menu> host setup and management> deploy> sensor downloads> locate sensor installer for OS» copy ID checksum or CCID> run your deployment tool to use this cmd: <Installer_Filename> /install /quiet /norestart CID=<CCID></CCID></Installer_Filename>

52
Q

What are some automatic installation best practices?

A

-Conduct manual sensor test installations first
-Adjust and test the cmd line aspects
-Finalize the string that makes the installation work properly

53
Q

What command validates that a sensor is running on a host?

A

-sc.exe query csagent

54
Q

What is beneficial about installing sensors manually?

A

-Best for small number of sensor installations

55
Q

Sensors are installed 2 different ways. What are they?

A

-Manual
-automatic

56
Q

How to install sensors manually?

A

Falcon main menu> host setup and management> deploy> sensor downloads>locate sensor installer for OS> copy ID checksum or CCID> double click .pkg file> accept license agreements and input checksum/ccid> yes to allow installation>

57
Q

What is beneficial about installing sensors automatically?

A

-Best for large number of installations