Question 6

Within the MITRE-Based Falcon Detections Framework, what is the correct way to interpret Keep Access > Persistence > Create Account?
  • Question 7

    When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?
  • Question 8

    What happens when a quarantined file is released?
  • Question 9

    The Falcon platform will show a maximum of how many detections per day for a single Agent Identifier (AID)?
  • Question 10

    How are processes on the same plane ordered (bottom 'VMTOOLSD.EXE' to top CMD.EXE')?