Question 21

When creating new IOCs in IOC management, which of the following fields must be configured?
  • Question 22

    Which of the following applies to Custom Blocking Prevention Policy settings?
  • Question 23

    Even though you are a Falcon Administrator, you discover you are unable to use the "Connect to Host" feature to gather additional information which is only available on the host. Which role do you need added to your user account to have this capability?
  • Question 24

    Why is it critical to have separate sensor update policies for Windows/Mac/*nix?
  • Question 25

    Which option allows you to exclude behavioral detections from the detections page?